PHPGurukul Employee Record Management System
cpe:2.3:a:phpgurukul:employee_record_management_system:*:*:*:*:*:*:*
- 1.3
A critical SQL injection vulnerability has been identified in version 1.3 of the PHPGurukul Employee Record Management System. The issue arises in the file registererms.php, where the Email parameter is manipulated to inject malicious SQL queries. This vulnerability can be exploited remotely, allowing attackers to access the database without authorization, potentially leading to data modification, deletion, or unauthorized information retrieval.
Exploitation of this vulnerability allows for SQL injection, where an attacker can inject malicious SQL queries into the database. This could result in unauthorized database access, data manipulation, deletion, or retrieval of sensitive information.
To reproduce this vulnerability, send a POST request to the registererms.php file with crafted payloads that exploit the boolean-based blind SQL injection vulnerability in the Email parameter. The injection can be verified by observing the application's response, which may indicate successful exploitation, such as bypassing authentication or accessing restricted data.
No specific mitigation measures are known for this vulnerability. However, it is generally recommended to replace the affected product with an alternative that does not have this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.