Impact
The vulnerability in the /storage/admin/maintenance/manage_pricing.php endpoint allows an attacker to embed arbitrary SQL statements, enabling unauthorized read or write access to the database. This could result in viewing, altering, or deleting tenant pricing information, compromising the confidentiality, integrity, and availability of the system’s data.
Affected Systems
Sourcecodester Storage Unit Rental Management System version 1.0, specifically the admin maintenance pricing module. No vendor patch is listed, but the flaw exists in the open‑source code delivered in that release.
Risk and Exploitability
The flaw is exploitable over the network through HTTP requests to the vulnerable script. While authentication requirements are not explicitly documented, the endpoint resides in an admin area, suggesting that administrative credentials are likely needed. Because no exploit probability score is provided, the exact likelihood is unclear, but the combination of a web accessible entry point and lack of mitigation signals a moderate to high risk if the administrator interface is reachable.
OpenCVE Enrichment