Impact
The vulnerability is a classic SQL injection flaw in the login.php script of SourceCodester College Notes Gallery Management System. Attackers can manipulate the User parameter to inject arbitrary SQL and extract data, modify records, or cause denial of service. The weakness maps to CWE-74 and CWE-89.
Affected Systems
Affected are users running version 1.0 of SourceCodester College Notes Gallery Management System, which deploys the login.php file for authentication on web servers.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium impact, and the EPSS score of less than 1% suggests a very low likelihood of exploitation for the time being. Attackers can initiate the exploit remotely and may bypass authentication or exfiltrate data. The vulnerability is not listed in CISA KEV.
OpenCVE Enrichment