Impact
An SQL injection flaw exists in the /admin/AdminLogin.php script of code‑projects Task Management System 1.0. By manipulating the email or password parameters, an attacker can inject arbitrary SQL that is executed against the database. This flaw is a CWE‑74 combined with CWE‑89 and could expose, modify, or delete data in the system’s database, compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerable product is code‑projects Task Management System version 1.0, specifically the AdminLogin.php file. No alternative versions are listed. The product is hosted on code‑projects.org and its source is available on GitHub under the user littleRain1355.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity, and the EPSS score is not available, so the likelihood of exploitation is uncertain. The flaw is not listed in the CISA KEV catalog. Attackers can perform the injection remotely via crafted HTTP requests to the admin login endpoint, and an exploit has already been published, suggesting active use.
OpenCVE Enrichment