Impact
An unchanged SQL injection flaw exists in the writepartnerprefs function of partner_preference.php, allowing an attacker to manipulate the education parameter. The weakness permits arbitrary SQL commands to be executed against the database, leading to unauthorized data read, modification, or deletion. The impact zone is the application database, potentially exposing all user records and compromising data integrity.
Affected Systems
The vulnerability affects code‑projects Matrimonial System version 1.0. No other affected versions are listed. Systems running this exact version should be considered at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. Although not listed in CISA KEV, the public disclosure and remote execution potential mean that an attacker can trigger the flaw without local access. The likely attack vector is via an HTTP request to partner_preference.php with a crafted education parameter.
OpenCVE Enrichment