Vulnerability Description
Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These include: c-full, fname, mname,lname, gname, ocp, nation, mobno, email, board1, roll1, pyear1, board2, roll2, pyear2, sub1,marks1, sub2, course-short, income, category, ph, country, state, city, padd, cadd, and gender.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpgurukul | Student Record System | 3.20 |
Related Weaknesses (CWE)
References
- https://github.com/leexsoyoung/CVEs/blob/main/CVE-2024-44630.mdExploitThird Party Advisory
- https://phpgurukul.com/student-record-system-phpProduct
FAQ
What is CVE-2024-44630?
CVE-2024-44630 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These include: c-full, fname, mname,lname, gname, ocp, nation, mobno, email, board1, roll1...
How severe is CVE-2024-44630?
CVE-2024-44630 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-44630?
Check the references section above for vendor advisories and patch information. Affected products include: Phpgurukul Student Record System.