Impact
An input validation flaw in the /login/index.php file of Online Reviewer System 1.0 allows an attacker to manipulate the username or password fields, leading to a SQL injection vulnerability. The flaw permits execution of arbitrary SQL statements, which can compromise the confidentiality and integrity of the underlying data store.
Affected Systems
The affected product is Online Reviewer System 1.0 released by the code‑projects team. It is identified in the Common Platform Enumeration as fabian:online_reviewer_system:1.0.* and appears to be the only publicly available version noted in the advisory.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high impact on data. The EPSS score is listed as < 1%, suggesting low likelihood of exploitation in the wild. The vulnerability is not included in the CISA KEV catalog. Attack can be carried out remotely via the login interface, relying on injection of malicious input into the username and password fields as described in the CVE description.
OpenCVE Enrichment