PT-2025-22817 · Unknown · Phpgurukul Student Management System

Published

2025-05-23

·

Updated

2025-05-24

·

CVE-2024-51102

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHPGURUKUL Student Management System using PHP and MySQL version 1
Description The issue is related to multiple SQL injection vulnerabilities. These vulnerabilities are located at the "/studentrecordms/login.php" API endpoint, specifically via the username and password parameters.
Recommendations For PHPGURUKUL Student Management System using PHP and MySQL version 1, consider disabling the login functionality at the "/studentrecordms/login.php" endpoint until a patch is available. Restrict access to the username and password parameters in the affected API endpoint to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-51102

Affected Products

Phpgurukul Student Management System