SQL Injection Vulnerability in PHPGurukul Medical Card Generation System
CVE-2024-10301
7.2HIGH
Key Information:
- Vendor
PHPGurukul
- Vendor
- CVE Published:
- 23 October 2024
What is CVE-2024-10301?
A critical security vulnerability has been identified in the PHPGurukul Medical Card Generation System version 1.0. This issue resides in an unknown function within the file /admin/search-medicalcard.php, specifically affecting the Search component. The problem arises due to insufficient input validation, allowing attackers to manipulate the 'searchdata' parameter, which can lead to SQL injection attacks. This vulnerability can be exploited remotely, granting potential intruders unauthorized access to sensitive data stored in the database. The exploit has been publicly disclosed and can be used by malicious actors to compromise the security of affected installations.