PT-2024-34373 · Unknown · Phpgurukul Online Course Registration System

Burak

·

Published

2024-05-17

·

Updated

2025-03-03

·

CVE-2024-5064

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: PHPGurukul Online Course Registration System version 3.1
Description: A critical issue affects the processing of the file news-details.php, where the manipulation of the nid argument leads to SQL injection. This issue can be initiated remotely.
Recommendations: For PHPGurukul Online Course Registration System version 3.1, consider restricting access to the news-details.php file until a fix is available, and avoid using the nid argument in this context to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-5064

Affected Products

Phpgurukul Online Course Registration System