PT-2024-34511 · Unknown · Phpgurukul Beauty Parlour Management System

Abhijith Narayanan

·

Published

2024-10-31

·

Updated

2025-03-31

·

CVE-2024-51065

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Phpgurukul Beauty Parlour Management System version 1.1
Description: The issue is related to SQL Injection in the admin/index.php file via the username parameter. This allows for potential exploitation of the system.
Recommendations: For Phpgurukul Beauty Parlour Management System version 1.1, consider restricting access to the admin/index.php file until a patch is available. As a temporary workaround, avoid using the username parameter in the affected API endpoint.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-51065

Affected Products

Phpgurukul Beauty Parlour Management System