Impact
A SQL injection vulnerability exists in the Student Crud Operation application, specifically within the /edit.php component. The flaw arises from improper handling of the id argument, allowing remote attackers to inject malicious SQL. This can lead to unauthorized database access, data extraction, or modification, potentially compromising the confidentiality, integrity, and authenticity of stored student records.
Affected Systems
The affected product is code-projects Student Crud Operation version 1.0. No additional sub‑components are listed; the vulnerability originates from an unspecified function in the edit.php file.
Risk and Exploitability
With a CVSS score of 5.3, the vulnerability is considered moderate. EPSS data is unavailable and the issue is not listed in the CISA KEV catalog, indicating no public exploitation has been reported yet. The most likely attack vector involves remote exploitation via manipulating the id query parameter in the edit.php URL, which can be performed without authentication if the application does not enforce access controls.
OpenCVE Enrichment