Impact
The vulnerability is an SQL injection flaw in the email parameter of the login page (/index.php). By injecting SQL code, an attacker can manipulate database queries, potentially exfiltrating sensitive information or altering data. The flaw is exploitable remotely without authentication.
Affected Systems
The affected product is code‑projects Task Management System In PHP, version 1.0. The vulnerability impacts the login functionality exposed by index.php. No other versions or additional components are listed.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can trigger the flaw via a web request from any remote host. Given the lack of authentication requirement, the risk of exploitation is relatively high for environments where the system is publicly reachable.
OpenCVE Enrichment