Impact
A vulnerability exists in code-projects Matrimonial System 1.0 that allows attackers to inject arbitrary SQL through the search.php page. The injection can be triggered by manipulating the parameters sex, mothertongue, maritialstatus, country, state, religion, agemin, and agemax. When exploited, the attacker can read, modify or delete data stored in the database, compromising confidentiality and integrity. The flaw reflects the weaknesses identified by CWE-74 (Improper Neutralization of Input) and CWE-89 (SQL Injection).
Affected Systems
Victims using the code‑projects Matrimonial System 1.0 are affected. The vulnerability is located in the Regular Search component of the application. No other versions or products have been confirmed to be vulnerable, so the issue is limited to version 1.0 of this software.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% signals a low probability of exploitation at this time. The vulnerability has not been listed in the CISA KEV catalog. An attacker can launch the attack remotely by issuing crafted HTTP requests to the search.php endpoint, leveraging the uncontrolled input fields to inject arbitrary SQL statements. Because the attack is remote and the exploitation does not require additional privileges, the potential impact is significant if the underlying database credentials grant broad access.
OpenCVE Enrichment