CVE-2024-13085: PHPGurukul Land Record System login.php sql injection
A vulnerability, which was classified as critical, has been found in PHPGurukul Land Record System 1.0. Affected by this issue is some unknown functionality of the file /admin/login.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13085?
CVE-2024-13085 is classified as a critical vulnerability due to the potential for SQL injection.
How do I fix CVE-2024-13085?
To fix CVE-2024-13085, ensure to validate and sanitize all user inputs for the username parameter in the /admin/login.php file.
What type of attack can exploit CVE-2024-13085?
CVE-2024-13085 can be exploited through remote SQL injection attacks originating from the manipulation of the username argument.
Which version of PHPGurukul Land Record System is affected by CVE-2024-13085?
CVE-2024-13085 affects version 1.0 of PHPGurukul Land Record System.
What file contains the vulnerability CVE-2024-13085?
The vulnerability CVE-2024-13085 is found in the /admin/login.php file of PHPGurukul Land Record System.