Vulnerability Description
SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensitive information via a crafted payload to the $cshortname, $cfullname, and $cdate variables.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpgurukul | Student Record System | 3.20 |
Related Weaknesses (CWE)
References
- https://medium.com/@cnetsec/a-sql-injection-vulnerability-exists-in-the-student-Third Party Advisory
- https://phpgurukul.com/student-record-system-php/Product
FAQ
What is CVE-2024-27685?
CVE-2024-27685 is a vulnerability with a CVSS score of 7.1 (HIGH). SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensitive information via a crafted payload to the $cshortname, $cfullname, and $cdat...
How severe is CVE-2024-27685?
CVE-2024-27685 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-27685?
Check the references section above for vendor advisories and patch information. Affected products include: Phpgurukul Student Record System.