Vulnerability Description
A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2. The vulnerability allows attackers to bypass authentication and gain unauthorized access by injecting SQL commands into the username input field during the login process.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpgurukul | Online Fire Reporting System | 1.2 |
Related Weaknesses (CWE)
References
- https://github.com/MarkLee131/PoCs/blob/main/CVE-2024-34987.mdExploitThird Party Advisory
- https://www.exploit-db.com/exploits/51989ExploitThird Party Advisory
- https://github.com/MarkLee131/PoCs/blob/main/CVE-2024-34987.mdExploitThird Party Advisory
- https://www.exploit-db.com/exploits/51989ExploitThird Party Advisory
FAQ
What is CVE-2024-34987?
CVE-2024-34987 is a vulnerability with a CVSS score of 9.1 (CRITICAL). A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2. The vulnerability allows attackers to bypass authentication and gain unauthori...
How severe is CVE-2024-34987?
CVE-2024-34987 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-34987?
Check the references section above for vendor advisories and patch information. Affected products include: Phpgurukul Online Fire Reporting System.