SQL Injection Vulnerability in Vehicle Parking Management System by PHP Gurukul
CVE-2021-37806

5.9MEDIUM

Key Information:

Vendor
PHPgurukul
Vendor
CVE Published:
27 October 2021

Summary

The Vehicle Parking Management System (version 1.0) by PHP Gurukul is susceptible to an SQL Injection flaw that allows attackers to exploit time-based SQL injection on various endpoints. By leveraging the SLEEP(N) function, an attacker can manipulate the editid, viewid, and catename parameters to cause a delay in the server's response, which can further facilitate the extraction of sensitive data from the database. Tools such as sqlmap can be utilized for exploiting this vulnerability, raising concerns over potential data breaches if not promptly addressed.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.