SQL Injection Vulnerability in Vehicle Parking Management System by PHP Gurukul
CVE-2021-37806
5.9MEDIUM
Summary
The Vehicle Parking Management System (version 1.0) by PHP Gurukul is susceptible to an SQL Injection flaw that allows attackers to exploit time-based SQL injection on various endpoints. By leveraging the SLEEP(N) function, an attacker can manipulate the editid, viewid, and catename parameters to cause a delay in the server's response, which can further facilitate the extraction of sensitive data from the database. Tools such as sqlmap can be utilized for exploiting this vulnerability, raising concerns over potential data breaches if not promptly addressed.
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved