PT-2021-17501 · Unknown · Phpgurukul Beauty Parlour Management System

CVE-2021-27545

·

Published

2021-04-15

·

Updated

2023-11-14

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHPGurukul Beauty Parlour Management System version 1.0
Description The issue allows remote attackers to obtain sensitive database information by injecting SQL commands into the sername parameter in the "add-services.php" component.
Recommendations For PHPGurukul Beauty Parlour Management System version 1.0, avoid using the sername parameter in the affected "add-services.php" component until the issue is resolved. Consider temporarily restricting access to the "add-services.php" component to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27545

Affected Products

Phpgurukul Beauty Parlour Management System