PT-2020-18488 · Phpgurukul · Phpgurukul Small Crm
Published
2020-01-08
·
Updated
2023-03-01
·
CVE-2020-5511
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PHPGurukul Small CRM version 2.0
Description
The issue concerns an authentication bypass via SQL injection when logging into the administrator login page. This allows unauthorized access, potentially leading to further malicious activities.
Recommendations
For PHPGurukul Small CRM version 2.0, consider disabling the administrator login page until a patch is available to prevent exploitation of the SQL injection vulnerability. Restrict access to sensitive areas of the application to minimize the risk of unauthorized access.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpgurukul Small Crm