SQL Injection Vulnerability in Pre-School Enrollment by PHPGurukul
CVE-2023-47445
9.8CRITICAL
Key Information:
- Vendor
- PHPgurukul
- Vendor
- CVE Published:
- 15 November 2023
Summary
The Pre-School Enrollment application version 1.0 developed by PHPGurukul is susceptible to an SQL Injection attack via the username parameter on the preschool/admin/ page. This vulnerability allows an attacker to manipulate database queries executed by the application, potentially leading to unauthorized access to sensitive data and other malicious outcomes.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database