SQL Injection Vulnerability in Teacher Subject Allocation Management System by phpgurukul
CVE-2023-46025

4.9MEDIUM

Key Information:

Vendor
PHPgurukul
Vendor
CVE Published:
14 November 2023

Summary

An SQL Injection vulnerability exists in the teacher-info.php file of the Teacher Subject Allocation Management System version 1.0 by phpgurukul. This flaw allows attackers to manipulate the 'editid' parameter, potentially leading to unauthorized access to sensitive data stored within the system. Exploiting this vulnerability could compromise the integrity of user information, making it crucial for system administrators to apply patches and safeguard their applications.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.