CVE-2024-25351: SQL Injection
Published Feb 28, 2024
·Updated
SQL Injection vulnerability in /zms/admin/changeimage.php in PHPGurukul Zoo Management System 1.0 allows attackers to run arbitrary SQL commands via the editid parameter.
Affected Software
2 affected components
Phpgurukul Zoo Management System
Phpgurukul Zoo Management System=1.0
Event History
Feb 28, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25351?
CVE-2024-25351 has been classified as a high severity SQL Injection vulnerability.
2
How do I fix CVE-2024-25351?
To fix CVE-2024-25351, validate and sanitize input for the editid parameter in the changeimage.php file.
3
What version of PHPGurukul Zoo Management System is affected by CVE-2024-25351?
CVE-2024-25351 affects PHPGurukul Zoo Management System version 1.0.
4
Can CVE-2024-25351 allow unauthorized access to the database?
Yes, CVE-2024-25351 allows attackers to execute arbitrary SQL commands, which can lead to unauthorized access to the database.
5
Is CVE-2024-25351 a known vulnerability in cybersecurity?
Yes, CVE-2024-25351 is recognized as a known vulnerability that has been documented in various cybersecurity databases.