PT-2025-46971 · Phpgurukul · Phpgurukul Student Management System

Published

2025-11-14

·

Updated

2025-11-14

·

CVE-2024-55016

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHPGurukul Student Record Management System version 3.2.0
Description The PHPGurukul Student Record Management System version 3.2.0 is susceptible to SQL Injection. This issue affects the login.php file through the id and password parameters. Exploitation of this issue could allow an attacker to inject malicious SQL code, potentially gaining unauthorized access to the system or manipulating data.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the login.php file. Sanitize the id and password parameters before using them in SQL queries.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-55016

Affected Products

Phpgurukul Student Management System