CVE-2024-5135: PHPGurukul Directory Management System index.php sql injection
Published May 20, 2024
·Updated
A vulnerability was found in PHPGurukul Directory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-265211.
Affected Software
2 affected components
Phpgurukul Directory Management System
Phpgurukul Directory Management System=1.0
Event History
May 20, 2024
CVE Published
via MITRE·08:31 AM
Data Sourced
via MITRE·08:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Apr 8, 58462
Event
via NVD·01:56 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-5135?
CVE-2024-5135 is rated as a critical vulnerability.
2
What systems are affected by CVE-2024-5135?
CVE-2024-5135 affects PHPGurukul Directory Management System version 1.0.
3
What vulnerability type is CVE-2024-5135?
CVE-2024-5135 is an SQL injection vulnerability.
4
How do I fix CVE-2024-5135?
To fix CVE-2024-5135, validate and sanitize input for the 'username' parameter in /admin/index.php to prevent SQL injection.
5
Can CVE-2024-5135 be exploited remotely?
Yes, CVE-2024-5135 can be exploited remotely.