Impact
A vulnerability exists in the comment_count_user.php module of the code-projects Task Management System 1.0, where the task_id parameter is not properly sanitized. This allows an attacker to inject malicious SQL statements, enabling the execution of arbitrary database commands such as data exfiltration, modification, or deletion. The flaw is exploitable remotely and has already been publicly disclosed, indicating that attackers can trigger the attack over the network without any special privileges.
Affected Systems
The vulnerability affects the Task Management System produced by code-projects, specifically version 1.0. No other versions or components have been identified as impacted.
Risk and Exploitability
The CVSS score of 6.9 classifies the issue as medium severity. The EPSS score is not available, so the exploitation probability cannot be quantified; however, the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw remotely via manipulated task_id inputs, potentially leading to unauthorized data exposure or alteration. The lack of a public patch at this time increases the risk until an official fix is released.
OpenCVE Enrichment