Impact
A flaw in the login module of the SourceCodester and jkev Record Management System allows an attacker to craft a Username input that contains malicious SQL, causing the application to execute unintended database commands. Classified as CWE‑74 and CWE‑89, the vulnerability leads to the acquisition of, modification of, or removal of data stored in the database, thereby exposing confidentiality and integrity of sensitive information. The exploit is publicly available and can be triggered remotely via the login page.
Affected Systems
The records management systems developed by SourceCodester and jkev are impacted. The CVE entry does not specify a particular version, so any deployment that has not applied the relevant fix or mitigation could be vulnerable.
Risk and Exploitability
The base CVSS score of 6.9 places the flaw in the medium severity range. With no EPSS score provided and no listing in the CISA KEV catalog, the exact probability of exploitation is uncertain. Nevertheless, the remote attack vector and the existence of a public exploit indicate that an adversary can realistically acquire a foothold to compromise data if the vulnerability remains unmitigated.
OpenCVE Enrichment