Impact
Sourcecodester Online Men's Salon Management System version 1.0 contains a SQL Injection flaw in the file /msms/admin/appointments/view_appointment.php. The vulnerability allows an attacker to insert malicious SQL code through unsanitized user input, potentially enabling the retrieval or alteration of database contents. The impact is limited to data confidentiality and integrity, as it does not directly compromise authentication or availability.
Affected Systems
The affected system is the Simple Online Men's Salon Management System, version 1.0, a web application used for managing appointments in a men’s salon. Vendor information is not specified in the Advisory. The vulnerability resides in the administrative module that renders appointment views.
Risk and Exploitability
The CVSS score is 2.7, indicating low severity, and the EPSS score is less than 1 %, suggesting a very low likelihood of exploitation. The vulnerability is not catalogued in CISA’s KEV list. Attackers would need to reach the vulnerable endpoint, which is likely part of the administrator interface, and supply a crafted parameter to exploit the injection. No public exploit or proof‑of‑concept code is referenced, and the low scoring metrics imply that the risk to typical deployments is modest but still warrants investigation.
OpenCVE Enrichment