Impact
The flaw in residents.php allows an attacker to manipulate the Search argument, enabling the injection of arbitrary SQL. This results in improper input validation (CWE‑74) and classic SQL injection (CWE‑89). An attacker can read, modify, or delete resident records and potentially gain further privileges within the database, thereby compromising confidentiality and integrity of the resident data.
Affected Systems
code‑projects Barangay Resident Profiling Management System version 1.0. The affected component is the Resident Search Functionality in residents.php.
Risk and Exploitability
The CVSS score of 6.9 indicates that the vulnerability poses a moderate to high risk, and the EPSS score is not available, while the vulnerability is not listed in CISA KEV. Remote exploitation is possible, as the flaw can be triggered from outside the application without authentication. Because the exploit has been publicly disclosed, the likelihood of exploitation is non‑negligible.
OpenCVE Enrichment