PT-2021-17501 · Unknown · Phpgurukul Beauty Parlour Management System

Published

2021-04-15

·

Updated

2023-11-14

·

CVE-2021-27545

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHPGurukul Beauty Parlour Management System version 1.0
Description The issue allows remote attackers to obtain sensitive database information by injecting SQL commands into the sername parameter in the "add-services.php" component.
Recommendations For PHPGurukul Beauty Parlour Management System version 1.0, avoid using the sername parameter in the affected "add-services.php" component until the issue is resolved. Consider temporarily restricting access to the "add-services.php" component to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2021-27545

Affected Products

Phpgurukul Beauty Parlour Management System