CVE-2024-30998: SQL Injection
Published Apr 3, 2024
·Updated
SQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via the email parameter in the index.php component.
Affected Software
2 affected components
Phpgurukul Men Salon Management System
Phpgurukul Men Salon Management System=2.0
Event History
Apr 3, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30998?
CVE-2024-30998 is classified as a high severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2024-30998?
To fix CVE-2024-30998, you should sanitize and validate the email parameter input to prevent SQL Injection.
3
What systems are impacted by CVE-2024-30998?
CVE-2024-30998 affects PHPGurukul Men Salon Management System version 2.0.
4
What type of attack does CVE-2024-30998 enable?
CVE-2024-30998 enables SQL Injection attacks, allowing attackers to execute arbitrary code.
5
What information can attackers access through CVE-2024-30998?
Attackers exploiting CVE-2024-30998 can obtain sensitive information from the affected system.