PHPGurukul User Registration and Login System SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability exists in PHPGurukul User Registration & Login and User Management System version 3.3. The issue is located in the file '/admin/yesterday-reg-users.php', where the 'id' parameter is manipulated, allowing attackers to inject malicious SQL queries. This vulnerability can be exploited remotely, with a public exploit available.

Impact

Exploitation of this vulnerability allows unauthorized access to the database, where attackers can leak, modify, or delete data. Additionally, it could lead to full system control and service disruption.

Reproduction

The vulnerability can be reproduced by sending a GET request to '/loginsystem/admin/yesterday-reg-users.php' with a crafted 'id' parameter that includes a SQL injection payload. The injection can be verified by using a time-based blind SQL injection technique, such as making the database wait for a few seconds before responding.

Remediation

No specific remediation is known for this vulnerability.

Added: Apr 5, 2026, 5:19 AM
Updated: Apr 5, 2026, 5:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
3.8
exploitability
9.5
remediation
0.0
relevance
5.3
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.