Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jannick Tiger

#14595of 53,634
18.6Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2021-17128
8.8
2021-07-22
Unknown · Phpgurukul Student Record System · CVE-2021-26764
**Name of the Vulnerable Software and Affected Versions** PHPGurukul Student Record System version 4.0 **Description** The issue allows remote attackers to execute arbitrary SQL statements. This is achieved via the `id` parameter to the "edit-std.php" endpoint. **Recommendations** For PHPGurukul Student Record System version 4.0, consider restricting access to the "edit-std.php" endpoint until a patch is available. As a temporary workaround, avoid using the `id` parameter in the affected endpoint to minimize the risk of exploitation.
PT-2021-17129
9.8
2021-07-22
Unknown · Phpgurukul Student Record System · CVE-2021-26765
**Name of the Vulnerable Software and Affected Versions** PHPGurukul Student Record System version 4.0 **Description** The issue allows remote attackers to execute arbitrary SQL statements. This is achieved via the `sid` parameter to the "edit-sub.php" endpoint. **Recommendations** For PHPGurukul Student Record System version 4.0, consider restricting access to the `edit-sub.php` endpoint until a patch is available. As a temporary workaround, avoid using the `sid` parameter in the affected endpoint to minimize the risk of exploitation.