Impact
The vulnerability resides in the Admin Login Form of the code-projects Internship Management System 1.0 and allows an attacker to inject arbitrary SQL statements by manipulating the Password field. This flaw, characterized by the CWEs CWE-74 and CWE-89, can compromise the confidentiality, integrity, and availability of the database used by the system.
Affected Systems
The affected product is the code-projects Internship Management System version 1.0. The weakness is present in the file /admin/login.php of the Admin Login Form component. No additional product variants are listed.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the public availability of an exploit increases the risk of real-world attacks. The attack vector is remote, enabling an adversary to send crafted credentials directly to the login script from outside the trusted network. Successful exploitation would allow unauthorized access to the underlying database, potentially leading to data theft or modification.
OpenCVE Enrichment