First published: Sat Mar 30 2024(Updated: )
A vulnerability, which was classified as critical, was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. This affects an unknown part of the file /admin/forgot-password.php of the component Forgot Password Page. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258681 was assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
PHPGurukul Emergency Ambulance Hiring Portal | ||
PHPGurukul Emergency Ambulance Hiring Portal | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3088 is classified as a critical vulnerability.
CVE-2024-3088 affects the Forgot Password Page in the PHPGurukul Emergency Ambulance Hiring Portal.
CVE-2024-3088 is an SQL injection vulnerability.
To fix CVE-2024-3088, sanitize and validate user input in the username parameter in the affected PHP file.
CVE-2024-3088 can be exploited by manipulating the username argument in the /admin/forgot-password.php file.