Impact
Manipulation of an unknown function within the file cict_portal.sql causes sensitive information to be stored in plain text, exposing data that should remain confidential. This flaw enables an attacker to gain read access to credentials and other private details that the system processes, potentially leading to credential compromise and further exploitation. The vulnerability is classified as a moderate-severity disclosure, reflecting its impact on data confidentiality.
Affected Systems
SourceCodester Syllabus-Aligned Learning Management & Examination System version 1.0 is affected. The flaw resides in the database script cict_portal.sql, which handles data storage for the application. No other versions or components are confirmed affected at this time.
Risk and Exploitability
With a CVSS score of 6.9, the vulnerability presents a moderate risk. The exploit is available publicly and can be launched remotely, though the EPSS score is currently not provided. Because it is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is unknown, yet the remote nature of the attack vector and the cleartext storage compromise makes it a significant security concern.
OpenCVE Enrichment