Home

Description

A SQL Injection vulnerability was found in /covid-tms/password-recovery.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via the contactno POST request parameter.

PUBLISHED Reserved 2024-11-20 | Published 2024-11-27 | Updated 2024-11-27 | Assigner mitre

References

github.com/...urukul/COVID19/SQL Injection vulnerability.pdf

cve.org (CVE-2024-53603)

nvd.nist.gov (CVE-2024-53603)

Download JSON