First published: Sat Oct 19 2024(Updated: )
A vulnerability was found in PHPGurukul Boat Booking System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php of the component Sign In Page. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
PHPGurukul Boat Booking System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10156 has been declared as critical due to its potential for SQL injection.
To fix CVE-2024-10156, it is recommended to sanitize and validate user inputs in the Sign In Page to prevent SQL injection.
CVE-2024-10156 affects the Sign In Page in the /admin/index.php file of the PHPGurukul Boat Booking System 1.0.
CVE-2024-10156 is an SQL injection vulnerability caused by improper handling of the username argument.
CVE-2024-10156 affects PHPGurukul Boat Booking System version 1.0.