CVE-2023-5794

HIGH

PHPGurukul Online Railway Catering System 1.0 - SQL Injection via Login Username Parameter

Title source: llm
STIX 2.1

Description

A vulnerability was found in PHPGurukul Online Railway Catering System 1.0. It has been classified as critical. Affected is an unknown function of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-243600.

References (3)

Core 3
Core References
Third Party Advisory vdb-entry technical-description
https://vuldb.com/?id.243600
Third Party Advisory signature permissions-required
https://vuldb.com/?ctiid.243600

Scores

CVSS v3 7.3
EPSS 0.0005
EPSS Percentile 14.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-89
Status published
Products (1)
phpgurukul/online_railway_catering_management_system 1.0
Published Oct 26, 2023
Tracked Since Feb 18, 2026