PHPGurukul Art Gallery Management System SQL Injection Vulnerability in Change Image Functionality

Vulnerability

A critical SQL injection vulnerability has been identified in the PHPGurukul Art Gallery Management System version 1.1. The issue resides in the admin/changeimage.php file, where the editid parameter is manipulated, allowing attackers to inject malicious SQL queries. This vulnerability can be exploited remotely, leading to unauthorized database access, data manipulation, and potential system compromise.

Impact

Exploitation of this vulnerability allows for unauthorized database access, data modification or deletion, and access to sensitive information. It could also lead to complete system control and service disruption.

Reproduction

The vulnerability can be reproduced by sending a POST request to the admin/changeimage.php file with a crafted editid parameter that includes malicious SQL payloads. This can be done using tools like sqlmap, which automates the injection process and exploits the vulnerability.

Remediation

No specific mitigation measures are known for this vulnerability.

Added: Jun 21, 2025, 6:18 PM
Updated: Jun 21, 2025, 6:18 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
7.5
exploitability
6.8
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.