SQL Injection Vulnerability in User Registration & Login and User Management System
CVE-2024-48282
Currently unrated
Key Information:
- Vendor
PHPGurukul
- Vendor
- CVE Published:
- 15 October 2024
What is CVE-2024-48282?
A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the femail parameter in a POST HTTP request.
