Impact
The Student Web Portal contains a flaw in the valreg_passwdation function of signup.php. By manipulating the reg_passwd argument an attacker can inject SQL statements into the database query. The injection can lead to unauthorized disclosure, modification, or deletion of information and can be executed from a remote host.
Affected Systems
The vulnerability affects code-projects Student Web Portal version 1.0. Only this specific release is confirmed to be susceptible.
Risk and Exploitability
The CVSS score is 6.9, indicating moderate severity. The EPSS score is below 1 %, suggesting a low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Because the exploit is remote, attackers who can reach the signup page may craft malicious input, but no confirmed public exploits are known at this time.
OpenCVE Enrichment