PHPGurukul Complaint Management System
cpe:2.3:a:phpgurukul:complaint_management_system:*:*:*:*:*:*:*
- 2.0
A SQL injection vulnerability has been identified in PHPGurukul Complaint Management System version 2.0. The issue arises in the reset-password.php file, where the email and mobileno parameters can be manipulated to inject malicious SQL queries.
Exploitation of this vulnerability allows attackers to execute arbitrary SQL commands, potentially leading to unauthorized data access or manipulation.
To reproduce this vulnerability, send a request to the reset-password.php file with injected SQL payloads in the email and mobileno parameters. Use a time-based payload, such as 'sleep(10)', to obfuscate the attack and avoid detection.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.