Impact
A manipulated keyword argument in the action.php file of the Search Functionality can trigger an SQL injection, allowing a remote attacker to inject arbitrary SQL statements. This flaw can lead to unauthorized data disclosure, data alteration, or potential denial of service against the database. The official CVSS score of 6.9 indicates a moderate severity, reflecting that while exploitation is feasible, it may require some application‑level access to achieve full impact.
Affected Systems
The online shopping platform built by code‑projects, specifically version 1.0, contains the vulnerable script action.php within its search functionality. Users relying on this product should verify whether they are deploying the listed version and assess whether the search API is exposed to external traffic.
Risk and Exploitability
The vulnerability is exploitable remotely and has already been publicly disclosed, yet no patch or workaround has been officially released, and the EPSS score is not available, making the exact likelihood of exploitation uncertain. The CVSS score of 6.9 suggests a significant risk when an attacker can direct crafted input to the keyword parameter. As it is not listed in the CISA KEV catalog, there are no confirmed real‑world exploitations, but the flaw remains a valid attack vector for determined adversaries.
OpenCVE Enrichment