SQL Injection Vulnerability in PHPGurukul Land Record System
CVE-2024-13084
5.3MEDIUM
Summary
A significant vulnerability exists within PHPGurukul's Land Record System version 1.0, specifically in the /admin/search-property.php file. This weakness allows for SQL injection through the manipulation of the 'searchdata' argument, which can be exploited by attackers remotely. The exploit has been publicly disclosed and poses serious risks to data integrity and confidentiality. Organizations using this system should take immediate action to mitigate the risks associated with this vulnerability and ensure their data is protected from potential exploitation.
Affected Version(s)
Land Record System 1.0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Fergod (VulDB User)