Impact
A flaw in the admin_edit_employee.php page allows attackers to inject arbitrary SQL by manipulating the First_Name parameter. This can modify or read database contents, potentially exposing or tampering with employee records and compromising the integrity and confidentiality of the system.
Affected Systems
The vulnerability targets itsourcecode Online Frozen Foods Ordering System version 1.0, specifically the /admin/admin_edit_employee.php script. No other versions or components were identified as affected.
Risk and Exploitability
With a CVSS score of 5.1 the issue is of moderate severity, yet the EPSS score of less than 1% indicates a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, but an attacker can launch the exploit remotely using publicly available proof‑of‑concept code. Administrators should consider it a tangible threat until a patch or mitigation is in place.
OpenCVE Enrichment