Impact
The vulnerability exists in the administrative block_status.php file of 1000 Projects Portfolio Management System MCA version 1.0 or earlier. An attacker can supply a crafted value for the query parameter q, causing the unescaped input to be incorporated directly into an SQL statement. This permits remote execution of arbitrary SQL queries, potentially allowing the attacker to read, modify, or delete database records. The weakness is identified as CWE-89. The vulnerability score of 5.3 indicates moderate severity, with the attack vector being remote.
Affected Systems
The affected product is 1000 Projects Portfolio Management System MCA up to version 1.0. The vulnerability is tied to theadmin/block_status.php file. No additional product versions are listed, so any deployment of the specified version remains at risk.
Risk and Exploitability
Because the flaw permits remote SQL injection and the exploit code is publicly available, the likelihood of exploitation is significant. The CVSS score of 5.3 reflects moderate impact, but the absence of an EPSS score leaves precise probability estimates uncertain. The vulnerability is not yet listed in the CISA KEV catalog, though this does not eliminate the risk of abuse. Mitigation requires immediate vendor remediation or workarounds to prevent unauthenticated attackers from reaching the vulnerable endpoint.
OpenCVE Enrichment