CVE-2021-38833

CRITICAL

PHPGurukul AVMS <1.0 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows attackers to execute arbitrary SQL statements and to gain RCE.

Exploits (1)

exploitdb WORKING POC
by mari0x00 · pythonwebappsphp
https://www.exploit-db.com/exploits/50288

Scores

CVSS v3 9.8
EPSS 0.0043
EPSS Percentile 62.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
apartment_visitors_management_system_project/apartment_visitors_management_system 1.0
Published Sep 13, 2021
Tracked Since Feb 18, 2026