CVE-2024-27685: SQL Injection
Published Jun 25, 2025
·Updated
SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensitive information via a crafted payload to the $cshortname, $cfullname, and $cdate variables.
Affected Software
2 affected components
N/A Student Record system
Phpgurukul Student Record System=3.20
Event History
Jun 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27685?
CVE-2024-27685 has been classified as a high severity SQL Injection vulnerability.
2
How do I fix CVE-2024-27685?
To fix CVE-2024-27685, sanitize and validate all user inputs to prevent SQL Injection.
3
What systems are affected by CVE-2024-27685?
CVE-2024-27685 affects the Student Record system Using PHP and MySQL version 3.20.
4
What kind of data could be exposed due to CVE-2024-27685?
CVE-2024-27685 could potentially expose sensitive information stored in the database.
5
Can CVE-2024-27685 be exploited remotely?
Yes, CVE-2024-27685 can be exploited remotely by sending a crafted payload.