CVE-2024-55099: SQL Injection
Published Dec 12, 2024
·Updated
A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.
Affected Software
2 affected components
Phpgurukul Online Nurse Hiring System
Phpgurukul Online Nurse Hiring System=1.0
Event History
Dec 12, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-55099?
CVE-2024-55099 is considered a critical vulnerability due to the potential for unauthorized database access.
2
How do I fix CVE-2024-55099?
To fix CVE-2024-55099, sanitize user inputs and use prepared statements to prevent SQL injection.
3
Who is affected by CVE-2024-55099?
CVE-2024-55099 affects users of phpgurukul Online Nurse Hiring System version 1.0.
4
What type of vulnerability is CVE-2024-55099?
CVE-2024-55099 is a SQL Injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
5
What component is exploited in CVE-2024-55099?
CVE-2024-55099 exploits the /admin/index.php component of the phpgurukul Online Nurse Hiring System.