SQL Injection Vulnerability in Maid Hiring Management System by PHP Gurukul
CVE-2023-37689

4.8MEDIUM

Key Information:

Vendor
PHPgurukul
Vendor
CVE Published:
8 August 2023

Summary

The Maid Hiring Management System v1.0 has been identified with a SQL injection vulnerability located on the Booking Request page. This weakness could allow unauthorized access to the database, potentially enabling attackers to execute arbitrary SQL queries. Users of this system are advised to implement security measures to mitigate the risks associated with this vulnerability and ensure their application remains secure.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.