CVE-2024-10157: PHPGurukul Boat Booking System Reset Your Password Page password-recovery.php sql injection
A vulnerability was found in PHPGurukul Boat Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/password-recovery.php of the component Reset Your Password Page. The manipulation of the argument username/mobileno leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10157?
CVE-2024-10157 is rated as critical due to its potential for serious exploitation.
How can I fix CVE-2024-10157?
To fix CVE-2024-10157, it is recommended to immediately update the PHPGurukul Boat Booking System to the latest patched version.
What components are affected by CVE-2024-10157?
CVE-2024-10157 affects the Reset Your Password Page component, specifically the file /admin/password-recovery.php.
What kind of vulnerability is represented by CVE-2024-10157?
CVE-2024-10157 represents an SQL injection vulnerability stemming from improper handling of the username argument.
Which version of PHPGurukul Boat Booking System is affected by CVE-2024-10157?
CVE-2024-10157 specifically affects version 1.0 of the PHPGurukul Boat Booking System.