Impact
A vulnerability in the SourceCodester Medical Center Portal Management System allows an attacker to manipulate the ID parameter in emp_edit1.php, enabling execution of arbitrary SQL statements. This flaw can compromise the confidentiality, integrity, and availability of the underlying database, allowing attackers to read, modify, or delete sensitive employee data.
Affected Systems
SourceCodester Medical Center Portal Management System version 1.0 is affected; no other versions are listed.
Risk and Exploitability
The CVSS score of 6.9 denotes a medium severity, while an EPSS score of less than 1% indicates a low likelihood of current exploitation. The vulnerability is not present in the CISA KEV catalog. The attack is likely remote, requiring an attacker to craft a request that passes a malicious ID value to the web page; no special privileges beyond access to the portal are required, so unauthenticated or lightly authenticated users could potentially exploit it.
OpenCVE Enrichment