Impact
An undisclosed function in the /display.php file of SourceCodester Malawi Online Market 1.0 accepts an ID parameter that is not properly sanitized, allowing an attacker to inject SQL statements. The injection can be triggered remotely via crafted URLs or POST data, and a published exploit demonstrates that unauthorized database queries can be executed. The vulnerability falls under CWE-89 and CWE-74.
Affected Systems
The affected product is SourceCodester Malawi Online Market, version 1.0, distributed by SourceCodester. No other product versions or vendors are listed as affected by this specific flaw.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation in the wild. The vulnerability is not present in CISA’s KEV catalog, and no official patch has been publicly released as of the data provided. Because the flaw can be exploited remotely without any local privileges, it poses a significant risk to data confidentiality and integrity if an attacker gains access to the underlying database.
OpenCVE Enrichment