SQL Injection Vulnerability in PHPGurukul Complaint Management System
CVE-2024-13004
Key Information:
- Vendor
- PHPgurukul
- Vendor
- CVE Published:
- 29 December 2024
Badges
Summary
A vulnerability has been identified in PHPGurukul's Complaint Management System version 1.0, specifically within the admin functionality located in the file /admin/category.php. The issue arises from improper handling of the 'state' argument, enabling an SQL injection attack that can be executed remotely. This flaw exposes the database to unauthorized queries, which could lead to unauthorized data access or manipulation. Public disclosure of this vulnerability highlights the urgency for users to implement appropriate security measures to safeguard their systems.
Affected Version(s)
Complaint Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved