Impact
The vulnerability resides in the accommodation.php component of SourceCodester and janobe's Resort Reservation System 1.0. Manipulation of the query string parameter q allows attackers to inject arbitrary SQL statements, leading to unauthorized data access or modification. The flaw can be exploited remotely through a crafted HTTP request.
Affected Systems
The affected product is SourceCodester's Resort Reservation System and janobe's Resort Reservation System, both at version 1.0.
Risk and Exploitability
With a CVSS v3.1 score of 5.3, the vulnerability is considered medium severity. The EPSS score is below 1%, indicating a low likelihood of exploitation at this time, and the issue is not listed in the CISA KEV catalog. Attackers could exploit the vulnerability remotely by supplying a malicious value for the q parameter, potentially gaining unauthorized read or write access to the underlying database. While the probability of exploitation remains low, the potential impact includes data exposure and alteration of reservation records.
OpenCVE Enrichment