PT-2024-35731 · Unknown · Phpgurukul Vehicle Parking Management System
Mohammed Athif
·
Published
2024-12-02
·
Updated
2024-12-02
·
CVE-2024-53364
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PHPGURUKUL Vehicle Parking Management System version 1.13
Description
A SQL injection issue was found in the /users/view-detail.php endpoint, specifically affecting the
viewid parameter. Improper input sanitization allows attackers to inject malicious SQL queries.Recommendations
For PHPGURUKUL Vehicle Parking Management System version 1.13, consider disabling access to the /users/view-detail.php endpoint until a patch is available, or ensure proper input sanitization for the
viewid parameter to prevent SQL injection attacks.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpgurukul Vehicle Parking Management System