Impact
A flaw in the Admin Login Endpoint of code-projects Employee Management System allows an attacker to inject arbitrary SQL through the mailuid argument in /process/aprocess.php. The injection can be executed remotely over the web. The advisory does not specify the exact data impact, but the vulnerability is caused by failure to validate or sanitize the mailuid parameter and is classified as CWE-74 and CWE-89.
Affected Systems
code-projects Employee Management System is the affected product. No specific product version information is provided in the advisory.
Risk and Exploitability
The CVSS score is 6.9, indicating moderate severity. Public advisories report that an exploit has been published and is usable, but the exact exploitation likelihood is unknown. Attackers can reach the vulnerable endpoint from any remote host, making it a low-barrier remote attack vector. The specific impact of exploitation is not detailed in the advisory.
OpenCVE Enrichment