SQL Injection Vulnerability in PHPGurukul Daily Expense Tracker System
CVE-2020-10106
9.8CRITICAL
Summary
The PHPGurukul Daily Expense Tracker System version 1.0 contains a significant vulnerability due to improper validation of user inputs, allowing SQL injection via the email parameter in index.php or register.php. This flaw exposes the application to potential unauthorized access, enabling attackers to extract sensitive information from the MySQL database and facilitate login bypass. It is crucial for users to implement security measures to mitigate these risks and secure their data.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved