Needyamin Library Card System SQL Injection Vulnerability in card.php

Vulnerability

A critical SQL injection vulnerability has been identified in Needyamin Library Card System version 1.0. The issue arises in the file card.php, where the id parameter can be manipulated to execute arbitrary SQL commands. This vulnerability can be exploited remotely, potentially leading to unauthorized access to user data, database leaks, and exposure of admin panel credentials.

Impact

Exploitation of this vulnerability allows for SQL injection, enabling attackers to interfere with the application's database queries. This could result in unauthorized data access, data manipulation, or in some cases, executing administrative operations within the application.

Reproduction

The vulnerability can be reproduced by sending a request to card.php with a crafted id parameter that includes SQL injection payloads. For example, appending a SQL injection payload to the id parameter can exploit the vulnerability and manipulate the application's database queries.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.