PHPGurukul Company Visitor Management System search-visitor.php sql injection
CVE-2024-0651
Key Information:
- Vendor
- PHPGurukul
- Vendor
- CVE Published:
- 18 January 2024
Badges
Summary
A vulnerability exists in the PHPGurukul Visitor Management System 1.0 related to the search-visitor.php file, allowing attackers to execute SQL injection techniques remotely. This issue stems from an unknown function that fails to adequately validate user input. Consequently, malicious actors could exploit this vulnerability to manipulate database queries, leading to unauthorized data access or potential data corruption. As the exploit has been publicly disclosed, organizations using this system should take immediate action to mitigate the risk.
Affected Version(s)
Company Visitor Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved