SQL Injection Vulnerability in PHPGurukul Small CRM 1.0
CVE-2024-13001
5.3MEDIUM
Summary
An SQL injection vulnerability exists in PHPGurukul Small CRM 1.0, specifically in the handling of the email parameter within the /admin/index.php file. This security flaw allows an attacker to manipulate inputs and execute arbitrary SQL commands via a remote connection, significantly compromising the database security. As this issue has been publicly disclosed, it poses a serious risk to systems running the affected version of the product, making it crucial for administrators to apply appropriate security measures and updates to mitigate potential exploits.
Affected Version(s)
Small CRM 1.0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Havook (VulDB User)