First published: Sat Apr 08 2023(Updated: )
A vulnerability has been found in PHPGurukul BP Monitoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file password-recovery.php of the component Password Recovery. The manipulation of the argument emailid/contactno leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-225337 was assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bp Monitoring Management System Project Bp Monitoring Management System | =1.0 | |
=1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-1950 is critical with a severity value of 9.8.
The PHPGurukul BP Monitoring Management System version 1.0 and the Bp Monitoring Management System Project version 1.0 are affected by CVE-2023-1950.
CVE-2023-1950 affects the Password Recovery functionality of the PHPGurukul BP Monitoring Management System 1.0.
The Common Weakness Enumeration (CWE) for CVE-2023-1950 is CWE-89.
Yes, you can refer to the following links for more information about CVE-2023-1950: [Link 1](https://github.com/vsdwef/BP-Monitoring-Management-System/blob/main/password-recovery.php_SQL_English.pdf), [Link 2](https://vuldb.com/?ctiid.225337), [Link 3](https://vuldb.com/?id.225337).