SQL Injection Vulnerability in PHPGurukul Student Record System by PHPGurukul
CVE-2024-44630
6.5MEDIUM
What is CVE-2024-44630?
The PHPGurukul Student Record System version 3.20 contains vulnerabilities in its register.php file, where multiple parameters are susceptible to SQL injection attacks. Malicious actors can exploit these weaknesses by manipulating user inputs such as full name, email, mobile number, and various academic parameters. This exploitation could lead to unauthorized access to sensitive data, alteration of database entries, and potentially full control over the database. It's imperative for users of this system to implement security measures to safeguard against these vulnerabilities.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
