SQL Injection Vulnerability in PHPGurukul Small CRM 1.0
CVE-2024-13001

5.3MEDIUM

Key Information:

Vendor
PHPgurukul
Status
Vendor
CVE Published:
29 December 2024

Summary

An SQL injection vulnerability exists in PHPGurukul Small CRM 1.0, specifically in the handling of the email parameter within the /admin/index.php file. This security flaw allows an attacker to manipulate inputs and execute arbitrary SQL commands via a remote connection, significantly compromising the database security. As this issue has been publicly disclosed, it poses a serious risk to systems running the affected version of the product, making it crucial for administrators to apply appropriate security measures and updates to mitigate potential exploits.

Affected Version(s)

Small CRM 1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Havook (VulDB User)
.