Impact
The vulnerability resides in ForPass.php of the Online Job Portal System and allows an attacker to inject arbitrary SQL through the txtUserName parameter. This flaw is a classic SQL injection (CWE‑74/CWE‑89) that can compromise the confidentiality and integrity of the database and potentially lead to data tampering or disclosure. The impact is limited to the data returned by the affected query, but a successful exploitation could expose or modify sensitive user information stored within the portal database.
Affected Systems
Affected product: code‑projects Online Job Portal System version 1.0. No patch version is listed. The flaw is present in the password recovery component and can be reached via the remote web interface.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack is remote and leverages direct user input to manipulate the SQL query. Given that the exploit has been disclosed publicly and may be used, the risk is non‑negligible and warrants timely remediation.
OpenCVE Enrichment