SQL Injection Vulnerability in PHPGurukul Daily Expense Tracker System
CVE-2020-10106

9.8CRITICAL

Key Information:

Vendor
PHPgurukul
Vendor
CVE Published:
5 March 2020

Summary

The PHPGurukul Daily Expense Tracker System version 1.0 contains a significant vulnerability due to improper validation of user inputs, allowing SQL injection via the email parameter in index.php or register.php. This flaw exposes the application to potential unauthorized access, enabling attackers to extract sensitive information from the MySQL database and facilitate login bypass. It is crucial for users to implement security measures to mitigate these risks and secure their data.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.