CVE-2021-37807: SQL Injection
An SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the /checkavailability.php endpoint that serves as a checker whether a new user's email is already exist within the database.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SQL Injection vulnerability?
The vulnerability ID for this SQL Injection vulnerability is CVE-2021-37807.
Where does the SQL Injection vulnerability exist?
The SQL Injection vulnerability exists in the email parameter on the /check_availability.php endpoint of the Online Shopping Portal 3.1.
How can an attacker exploit this SQL Injection vulnerability?
An attacker can exploit this SQL Injection vulnerability by injecting malicious SQL code into the email parameter to manipulate the database queries.
What is the severity of CVE-2021-37807?
The severity of CVE-2021-37807 is high, with a CVSS score of 7.5.
Is there a fix available for this SQL Injection vulnerability?
No specific fix information is provided in the vulnerability report. It is recommended to update to a patched version or apply security measures to mitigate the risk.