Impact
A SQL injection flaw exists in the email input field of the login page of PHPGurukul Daily Expense Tracker System. By sending malicious SQL through the email parameter, an attacker can alter or extract database records. The vulnerability is tied to CWE-74 and CWE-89, indicating that the application does not properly validate or escape composed input before inclusion in a query. Remote exploitation is possible and the vulnerability has public exploits available.
Affected Systems
Version 1.1 of PHPGurukul Daily Expense Tracker System contains the flaw. The vulnerable code resides in /dets/index.php, inside the login component. Any installation that hosts this version and exposes the login endpoint to the internet is susceptible. No other versions are documented as affected.
Risk and Exploitability
The CVSS score of 6.9 signals a moderate-to-high risk. The EPSS score is less than 1%, indicating a low probability of exploitation in the wild; however, the presence of publicly available exploits raises the likelihood of an attack. The flaw is not listed in the CISA KEV catalog, yet the ability for a remote attacker to trigger a fully functional injection suggests a real threat exists for exposed deployments.
OpenCVE Enrichment