Impact
A flaw in SourceCodester Simple Responsive Tourism Website 1.0 permits SQL injection through the Registration component’s Username parameter. The weakness is identified as CWE-89 and CWE-74, allowing an attacker to manipulate the SQL query that stores or retrieves user data. Successful exploitation can lead to unauthorized reading or modification of database contents, potentially exposing personal information or enabling further attacks such as credential harvesting.
Affected Systems
SourceCodester Simple Responsive Tourism Website version 1.0, specifically the /classes/Master.php?f=register registration endpoint within the Registration component.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating a moderate risk level, while the EPSS score is less than 1 %, suggesting a low current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. An attacker could trigger the issue remotely via a web request that supplies a crafted Username value; a published exploit demonstrates that the flaw can be leveraged in practice.
OpenCVE Enrichment