Impact
The vulnerability allows an attacker to inject malicious SQL code through the Status argument in all-tickets.php. This manipulation can pivot the database engine to execute arbitrary SQL statements, potentially exposing, altering, or deleting sensitive data stored by the application.
Affected Systems
The affected product is the Simple Food Ordering System by code-projects, version 1.0. The vulnerability resides in all-tickets.php and is specific to this version of the application.
Risk and Exploitability
The CVSS score of 5.3 places this issue in the medium severity range, while an EPSS score below 1% indicates a low probability of active exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is remote, as the attacker can trigger the injection from an external environment by supplying crafted values for the Status parameter.
OpenCVE Enrichment