PT-2023-29806 · Unknown · Phpgurukul Teacher Subject Allocation Management System
Ersinerenler
·
Published
2023-11-14
·
Updated
2023-11-17
·
CVE-2023-46024
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
phpgurukul Teacher Subject Allocation Management System version 1.0
Description
The issue allows attackers to execute arbitrary SQL commands and obtain sensitive information. This is achieved via the
searchdata parameter in the "index.php" file.Recommendations
For phpgurukul Teacher Subject Allocation Management System version 1.0, consider restricting access to the
searchdata parameter in the "index.php" file until a patch is available. As a temporary workaround, avoid using the searchdata parameter to minimize the risk of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpgurukul Teacher Subject Allocation Management System