Impact
A flaw in the Simple Laundry System 1.0 file /modstaffinfo.php allows attackers to inject SQL code by manipulating the userid argument. This can lead to unauthorized reading, modification or deletion of database records, potentially exposing sensitive customer information and disrupting business operations.
Affected Systems
The vulnerability affects the Simple Laundry System from code‑projects, specifically version 1.0. Systems running this build, particularly the /modstaffinfo.php component, must be evaluated for exposure.
Risk and Exploitability
The CVSS base score of 6.9 indicates a medium to high impact if exploited. The EPSS score is less than 1%, showing a low overall exploitation probability, but the CVE description states that an exploit has already been released to the public, so attackers can attempt it immediately. The attack vector is remote, requiring web access to the affected application and the ability to supply a crafted userid parameter. Although publicly available exploits are not yet confirmed to be widely used, the presence of a known exploit script means that administrators should not delay remediation.
OpenCVE Enrichment