Arbitrary SQL Command Execution Vulnerability in User Registration & Login and User Management System 3.2
CVE-2024-48280
Currently unrated
Key Information:
- Vendor
PHPGurukul
- Vendor
- CVE Published:
- 15 October 2024
What is CVE-2024-48280?
A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request.
