CVE-2024-54810: SQL Injection
A SQL Injection vulnerability was found in /preschool/admin/password-recovery.php in PHPGurukul Pre-School Enrollment System Project v1.0, which allows remote attackers to execute arbitrary code via the mobileno parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54810?
CVE-2024-54810 is classified as a high severity vulnerability due to the potential for remote attackers to execute arbitrary code.
How can I fix CVE-2024-54810?
To fix CVE-2024-54810, sanitize and validate all user inputs, particularly the mobileno parameter in the password-recovery.php file.
What type of vulnerability is CVE-2024-54810?
CVE-2024-54810 is a SQL Injection vulnerability that allows attackers to manipulate database queries.
Which software is affected by CVE-2024-54810?
CVE-2024-54810 affects PHPGurukul Pre-School Enrollment System Project version 1.0.
What are the potential impacts of CVE-2024-54810?
The potential impacts of CVE-2024-54810 include unauthorized data access and the execution of arbitrary code on affected systems.