CVE-2024-28323

The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a potential security vulnerability related to user input validation. The script retrieves user-provided date inputs without proper validation, making it susceptible to SQL injection attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpgurukul:user_registration_\&_login_and_user_management_system:3.1:*:*:*:*:*:*:*

History

01 Apr 2025, 16:16

Type Values Removed Values Added
References () https://packetstormsecurity.com/files/177168/User-Registration-And-Login-And-User-Management-System-3.1-SQL-Injection.html - () https://packetstormsecurity.com/files/177168/User-Registration-And-Login-And-User-Management-System-3.1-SQL-Injection.html - Exploit
References () https://sospiro014.github.io/User-Registration-And-Login-And-User-Management-System-3.1-SQL-Injection - () https://sospiro014.github.io/User-Registration-And-Login-And-User-Management-System-3.1-SQL-Injection - Exploit, Third Party Advisory
CPE cpe:2.3:a:phpgurukul:user_registration_\&_login_and_user_management_system:3.1:*:*:*:*:*:*:*
First Time Phpgurukul
Phpgurukul user Registration \& Login And User Management System

21 Nov 2024, 09:06

Type Values Removed Values Added
References () https://packetstormsecurity.com/files/177168/User-Registration-And-Login-And-User-Management-System-3.1-SQL-Injection.html - () https://packetstormsecurity.com/files/177168/User-Registration-And-Login-And-User-Management-System-3.1-SQL-Injection.html -
References () https://sospiro014.github.io/User-Registration-And-Login-And-User-Management-System-3.1-SQL-Injection - () https://sospiro014.github.io/User-Registration-And-Login-And-User-Management-System-3.1-SQL-Injection -

26 Aug 2024, 20:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-89

24 Apr 2024, 02:15

Type Values Removed Values Added
Summary
  • (es) El archivo bwdates-report-result.php en Phpgurukul User Registration & Login and User Management System 3.1 contiene una posible vulnerabilidad de seguridad relacionada con la validación de las entradas del usuario. El script recupera entradas de fechas proporcionadas por el usuario sin la validación adecuada, lo que lo hace susceptible a ataques de inyección SQL.
References
  • () https://sospiro014.github.io/User-Registration-And-Login-And-User-Management-System-3.1-SQL-Injection -

14 Mar 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-14 14:15

Updated : 2025-04-01 16:16


NVD link : CVE-2024-28323

Mitre link : CVE-2024-28323

CVE.ORG link : CVE-2024-28323


JSON object : View

Products Affected

phpgurukul

  • user_registration_\&_login_and_user_management_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')