Impact
The discovered flaw resides in the "signup" action of /social/ajax.php. By manipulating the email argument an unauthenticated attacker can inject arbitrary SQL statements into the database, enabling read, modify, or delete operations on stored data. The vulnerability is exploitable remotely, and a publicly available exploit exists, raising the risk of data compromise and integrity loss.
Affected Systems
SourceCodester Photo Share Website, version 1.0, is the only product listed as affected. No additional vendors or versions are cited in the CVE data.
Risk and Exploitability
The CVSS score of 6.9 reflects medium to high severity. While EPSS is not available, the presence of a public exploit and the remote nature of the attack suggest a non‑negligible risk. The vulnerability is not yet listed in the CISA KEV catalog, but attackers can target the exposed signup endpoint from external networks to exploit the SQL injection.
OpenCVE Enrichment