CVE-2024-13001: PHPGurukul Small CRM index.php sql injection
A vulnerability was found in PHPGurukul Small CRM 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13001?
CVE-2024-13001 is classified as a critical vulnerability.
How can I fix CVE-2024-13001?
To fix CVE-2024-13001, it is recommended to upgrade to the latest version of PHPGurukul Small CRM that addresses the SQL injection issue.
What type of vulnerability is CVE-2024-13001?
CVE-2024-13001 is a SQL injection vulnerability that affects the email parameter in the /admin/index.php file.
Can CVE-2024-13001 be exploited remotely?
Yes, CVE-2024-13001 can be exploited remotely, allowing attackers to manipulate the SQL queries.
What software is affected by CVE-2024-13001?
CVE-2024-13001 affects PHPGurukul Small CRM version 1.0.