Unknown · Phpgurukul Student Record System · CVE-2021-26764
**Name of the Vulnerable Software and Affected Versions**
PHPGurukul Student Record System version 4.0
**Description**
The issue allows remote attackers to execute arbitrary SQL statements. This is achieved via the `id` parameter to the "edit-std.php" endpoint.
**Recommendations**
For PHPGurukul Student Record System version 4.0, consider restricting access to the "edit-std.php" endpoint until a patch is available. As a temporary workaround, avoid using the `id` parameter in the affected endpoint to minimize the risk of exploitation.