PHPGurukul User Registration & Login and User Management System
cpe:2.3:a:phpgurukul:user_registration_&_login_and_user_management_system:*:*:*:*:*:*:*
- 3.3
A SQL injection vulnerability exists in PHPGurukul User Registration & Login and User Management System version 3.3. The issue is located in the file '/admin/yesterday-reg-users.php', where the 'id' parameter is manipulated, allowing attackers to inject malicious SQL queries. This vulnerability can be exploited remotely, with a public exploit available.
Exploitation of this vulnerability allows unauthorized access to the database, where attackers can leak, modify, or delete data. Additionally, it could lead to full system control and service disruption.
The vulnerability can be reproduced by sending a GET request to '/loginsystem/admin/yesterday-reg-users.php' with a crafted 'id' parameter that includes a SQL injection payload. The injection can be verified by using a time-based blind SQL injection technique, such as making the database wait for a few seconds before responding.
No specific remediation is known for this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.