Impact
A SQL injection vulnerability exists in the /login.php file of the code‑projects Online Shopping System 1.0. The unvalidated email argument allows a malicious user to inject arbitrary SQL via the Login component. The flaw is a CWE‑74 and CWE‑89 weakness that could enable an attacker to read, modify, or delete data in the underlying database, potentially leading to compromise of customer information or disruption of service.
Affected Systems
The affected product is code‑projects Online Shopping System version 1.0. Attackers can target the login endpoint directly from the internet and exploit the injection flaw in the email parameter.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity. Exploitation is possible remotely and a proof‑of‑concept has been made public, yet the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the presence of a public exploit and the remote attack vector elevate the risk, warranting prompt attention.
OpenCVE Enrichment