Impact
An unknown function within the chk.php file of the Project Management System’s login component can be manipulated to inject arbitrary SQL statements. This flaw allows an attacker to potentially bypass authentication or retrieve sensitive data from the database, compromising confidentiality and integrity of the stored information. The vulnerability is classified as a CWE-74/89 injection issue and is not limited to a single user, since the flaw can be exploited over the network.
Affected Systems
The affected product is code‑projects Project Management System version 1.0. No other affected versions are listed in the current data.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the injection remotely by sending crafted requests to the chk.php endpoint, and the exploit has already been publicly disclosed. Because the flaw resides in the authentication functionality, it offers a significant impact if successfully exploited.
OpenCVE Enrichment