CVE-2024-3088: PHPGurukul Emergency Ambulance Hiring Portal Forgot Password Page forgot-password.php sql injection
A vulnerability, which was classified as critical, was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. This affects an unknown part of the file /admin/forgot-password.php of the component Forgot Password Page. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258681 was assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3088?
CVE-2024-3088 is classified as a critical vulnerability.
What component is affected by CVE-2024-3088?
CVE-2024-3088 affects the Forgot Password Page in the PHPGurukul Emergency Ambulance Hiring Portal.
What type of vulnerability is CVE-2024-3088?
CVE-2024-3088 is an SQL injection vulnerability.
How do I fix CVE-2024-3088?
To fix CVE-2024-3088, sanitize and validate user input in the username parameter in the affected PHP file.
What can be exploited in CVE-2024-3088?
CVE-2024-3088 can be exploited by manipulating the username argument in the /admin/forgot-password.php file.