Impact
A SQL injection vulnerability exists in the PHPGurukul Student Information System version 1.0 due to improper handling of the ID argument in the student_edit1.php script. By manipulating this argument, an attacker can inject arbitrary SQL commands, potentially allowing unauthorized retrieval or modification of sensitive student data and other database contents. The flaw is exploitable remotely and has already been demonstrated publicly.
Affected Systems
The vulnerability affects PHPGurukul’s Student Information System, specifically version 1.0, where the /student_edit1.php module is vulnerable. Administrators of this system should verify if they are running the referenced version and assess exposure of the file to external users.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the absence of an EPSS score prevents precise risk quantification, though the public availability of the exploit suggests it can be used by attackers with remote access. The flaw is not listed in the CISA KEV catalog, but because it is remotely exploitable and already demonstrated, systems remain at risk of data breaches or unauthorized database manipulation.
OpenCVE Enrichment