Impact
A flaw in the login.php component of code-projects Internship Management System version 1.0 permits manipulation of the Password input field to trigger SQL injection. By constructing a malicious value for the Password parameter, an attacker can cause the server to execute arbitrary SQL statements when the login page processes the request. This behavior can be triggered remotely without prior authentication, and the vulnerability has publicly available exploit code that could be employed by adversaries.
Affected Systems
All deployments of code‑projects Internship Management System, specifically version 1.0, are affected because the vulnerable code resides in login.php. The issue is tied to that exact release and does not apply to other versions.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating moderate severity. The EPSS score is unavailable, and it is not listed in the CISA KEV catalog. An attacker can trigger the flaw by sending a crafted HTTP request to the login page from any network location. The known public exploit demonstrates that the vulnerability can be leveraged to cause arbitrary SQL commands to run against the backend database, potentially compromising data integrity.
OpenCVE Enrichment