Description
A vulnerability was determined in PHPGurukul Online Course Registration System up to 3.1. This impacts an unknown function of the file /onlinecourse/admin/manage-students.php. This manipulation of the argument id/cid causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Problem types
Product status
3.1
Timeline
| 2026-01-08: | Advisory disclosed |
| 2026-01-08: | VulDB entry created |
| 2026-01-22: | VulDB entry last update |
Credits
angelkate (VulDB User)
References
vuldb.com/?id.340130 (VDB-340130 | PHPGurukul Online Course Registration System manage-students.php sql injection)
vuldb.com/?ctiid.340130 (VDB-340130 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.733328 (Submit #733328 | PHPGurukul Online Course Registration System ≤ 3.1 SQL Injection Vulnerability)
vuldb.com/?submit.733331 (Submit #733331 | PHPGurukul Online Course Registration System ≤ 3.1 SQL Injection (Duplicate))
note-hxlab.wetolink.com/share/cU33RBoPPAF0
note-hxlab.wetolink.com/share/Tma34bofeB2L
phpgurukul.com/