SQL Injection Vulnerability in Directory Management System by PHP Gurukul
CVE-2022-31383
9.8CRITICAL
Summary
The Directory Management System v1.0 developed by PHP Gurukul is susceptible to a SQL injection vulnerability that can be exploited via the 'editid' parameter in the view-directory.php script. This security flaw allows attackers to manipulate database queries, potentially leading to unauthorized access to sensitive data and the ability to alter database content. It is crucial for users of this product to apply necessary patches and implement security measures to mitigate this risk.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved