SQL Injection Vulnerability in PHPGurukul Land Record System
CVE-2024-13084

5.3MEDIUM

Key Information:

Vendor
PHPgurukul
Vendor
CVE Published:
31 December 2024

Summary

A significant vulnerability exists within PHPGurukul's Land Record System version 1.0, specifically in the /admin/search-property.php file. This weakness allows for SQL injection through the manipulation of the 'searchdata' argument, which can be exploited by attackers remotely. The exploit has been publicly disclosed and poses serious risks to data integrity and confidentiality. Organizations using this system should take immediate action to mitigate the risks associated with this vulnerability and ensure their data is protected from potential exploitation.

Affected Version(s)

Land Record System 1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Fergod (VulDB User)
.