PT-2024-22393 · Unknown · Phpgurukul User Registration & Login/User Management System

Sospiro

·

Published

2024-03-14

·

Updated

2025-04-01

·

CVE-2024-28323

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Phpgurukul User Registration & Login and User Management System version 3.1
Description The issue is related to user input validation in the bwdates-report-result.php file. It retrieves user-provided date inputs without proper validation, making it susceptible to SQL injection attacks.
Recommendations For Phpgurukul User Registration & Login and User Management System version 3.1, consider validating all user-provided inputs, especially date inputs, to prevent SQL injection attacks. As a temporary workaround, restrict access to the bwdates-report-result.php file until a proper fix is applied.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-28323

Affected Products

Phpgurukul User Registration & Login/User Management System