Impact
A SQL injection flaw exists in the cat_id parameter of the homeaction.php script in code‑projects Online Shopping System. By injecting unsanitized input, an attacker can manipulate database queries, potentially retrieving, modifying, or deleting sensitive data. The vulnerability is classified as CWE‑89 and CWE‑74.
Affected Systems
code‑projects Online Shopping System, version 1.0. The flaw appears in the homeaction.php component and is present in the publicly released 1.0 build.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. No EPSS rating is available, and the flaw is not listed in the CISA KEV catalog. Because the attack can be performed remotely and exploit code is publicly available, the likelihood of exploitation remains significant. Attackers can use the vulnerability to gain unauthorized database access over the network, potentially leading to data compromise or denial of service.
OpenCVE Enrichment