SQL Injection Vulnerability in Vehicle Parking Management System by PHP Gurukul
CVE-2021-37806
5.9MEDIUM
What is CVE-2021-37806?
The Vehicle Parking Management System (version 1.0) by PHP Gurukul is susceptible to an SQL Injection flaw that allows attackers to exploit time-based SQL injection on various endpoints. By leveraging the SLEEP(N) function, an attacker can manipulate the editid, viewid, and catename parameters to cause a delay in the server's response, which can further facilitate the extraction of sensitive data from the database. Tools such as sqlmap can be utilized for exploiting this vulnerability, raising concerns over potential data breaches if not promptly addressed.