PT-2024-36423 · Unknown · Phpgurukul Park Ticketing Management System

Published

2024-12-12

·

Updated

2024-12-13

·

CVE-2024-54811

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPGurukul Park Ticketing Management System version 1.0
Description A SQL injection issue in the /index.php file of PHPGurukul Park Ticketing Management System allows an attacker to execute arbitrary SQL commands via the login parameter. This enables the attacker to manipulate the database, potentially leading to unauthorized data access or modification.
Recommendations For PHPGurukul Park Ticketing Management System version 1.0, consider disabling the login parameter in the /index.php file as a temporary workaround until a patch is available. Restrict access to the /index.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-54811

Affected Products

Phpgurukul Park Ticketing Management System