Impact
The vulnerability is a remote SQL injection flaw that allows an attacker to manipulate the User argument processed by an unidentified function within the /login.php page of SourceCodester Medical Center Portal Management System 1.0. The injected SQL can be used to read, modify, or delete database contents, leading to data exposure or integrity compromise. This weakness falls under the CWE‑74 (Builds a SQL Query from Unsanitized Data) and CWE‑89 (Improper Neutralization of Special Elements used in an SQL Command). No authentication prerequisite beyond access to the web login endpoint is required.
Affected Systems
Systems running SourceCodester Medical Center Portal Management System 1.0 are affected. No superseded versions are listed; the issue remains present in the specific 1.0 release.
Risk and Exploitability
The CVSS score of 6.9 signals moderate impact, while the EPSS score of less than 1% indicates a low probability of exploitation today. The vulnerability is not cataloged in CISA’s KEV list, but an active public exploit makes reliance on this system risky. The likely attack vector is remote delivery of malicious input to the login endpoint over HTTP or HTTPS, which could allow bypass of authentication and direct interaction with the database.
OpenCVE Enrichment