Impact
A flaw exists in the forgot-password.php script of the PHPGurukul Daily Expense Tracker System that allows attackers to supply crafted values for the email or contactno parameters. Those are incorporated directly into a database query, providing a classic SQL injection vector. If exploited, an adversary can read from, modify, or delete records in the underlying database, resulting in loss of confidentiality of expense data and potential integrity violations.
Affected Systems
The vulnerability is present in PHPGurukul Daily Expense Tracker System version 1.1. Only the listed product and version are affected.
Risk and Exploitability
The CVSS score of 6.9 classifies the flaw as moderate severity, while the EPSS score of less than 1% suggests a very low exploitation probability in the current environment. The vulnerability is not listed in the CISA KEV catalog. Attack can be carried out remotely by merely sending a crafted request to the exposed script; the description does not specify whether authentication is required, so the exact scope of potential targets remains uncertain.
OpenCVE Enrichment