PoC Index

CVE-2024-34987

CRITICAL 9.1EPSS 0.6%

A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2. The vulnerability allows attackers to bypass authentication and gain unauthorized access by injecting SQL commands into the username input field during the login process.

CVSS v3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
0.61% chance of exploitation in the next 30 days, 47th percentile
Published
2024-06-03
Updated
2024-08-14

Proof-of-concept exploits (2)

References

Related