Impact
A flaw in the login component of the code-projects Task Management System allows an attacker to manipulate the Password argument in index.php and gain unauthorized access. This improper authentication (CWE-287) means that authenticated sessions can be established without possessing valid credentials, enabling an attacker to impersonate legitimate users or gain elevated privileges if the system does not enforce role checks afterward.
Affected Systems
The affected product is code-projects Task Management System version 1.0. No other versions are listed in the CNA data, so only systems running this exact release are known to be vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity flaw. EPSS data is not available, but the advisory states that exploitation is possible remotely and that the exploit is publicly available. Because the vulnerability is not listed in CISA’s KEV catalog, there is no known mass exploitation activity yet, but the remote nature of the attack and public exploit code make it noteworthy. The risk is moderate to high for exposed deployments that rely on this login mechanism without additional controls.
OpenCVE Enrichment