PT-2024-16174 · Unknown · Phpgurukul Medical Card Generation System

Delvy

·

Published

2024-10-23

·

Updated

2024-10-25

·

CVE-2024-10301

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPGurukul Medical Card Generation System version 1.0
Description A critical issue was found in the Search component of the system, specifically in the /admin/search-medicalcard.php file. The manipulation of the searchdata argument leads to SQL injection. This issue can be exploited remotely.
Recommendations For PHPGurukul Medical Card Generation System version 1.0, as a temporary workaround, consider restricting access to the /admin/search-medicalcard.php file until a patch is available. Avoid using the searchdata argument in the affected API endpoint until the issue is resolved.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10301

Affected Products

Phpgurukul Medical Card Generation System