SQL Injection Vulnerability in PHPGurukul Complaint Management System 2.0
CVE-2024-44658
6.5MEDIUM
Key Information:
- Vendor
PHPGurukul
- Vendor
- CVE Published:
- 17 November 2025
What is CVE-2024-44658?
The PHPGurukul Complaint Management System version 2.0 is susceptible to SQL Injection attacks due to improper validation of the subcategory and category parameters in subcategory.php. This vulnerability allows attackers to manipulate SQL queries, potentially gaining unauthorized access to sensitive data within the system. It is crucial for users of this software to apply the necessary security measures to mitigate the risk of exploitation.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
