Impact
The vulnerability resides in the adduser.php file of code-projects Online Shopping System 1.0. An attacker can inject arbitrary SQL through the unvalidated mobile parameter, which is directly passed to mysqli_query. This flaw falls under CWE‑74 and CWE‑89 and can allow the execution of malicious SQL statements.
Affected Systems
The affected product is code-projects Online Shopping System version 1.0. No other versions are listed; the vulnerability appears in that single version. Administrators who have access to the add user functionality are at risk.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity and the EPSS is not available, but the exploit has been published and can be carried out remotely. The vulnerability is not listed in the CISA KEV catalog. Attackers who can reach the admin interface could manipulate database contents or extract sensitive data. The lack of input sanitization makes exploitation trivial in the absence of other access controls.
OpenCVE Enrichment