CVE-2024-55016
MEDIUMCVSS 6.5/10EPSS 0.21%
Last modified
CVE-2024-55016 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phpgurukul | Student Record System | 3.20 |
References
- https://github.com/leexsoyoung/CVEs/blob/main/CVE-2024-55016.mdExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-55016?
PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php.
How severe is CVE-2024-55016?
CVE-2024-55016 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2024-55016?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-54999MonicaHQ v4.1.2 was discovered to contain a Client-Side Inje…6.5
- CVE-2024-5500Inappropriate implementation in Sign-In in Google Chrome pri…6.5
- CVE-2024-55000Sourcecodester House Rental Management system v1.0 is vulner…5.4
- CVE-2024-55008JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability…7.5
- CVE-2024-55009A reflected cross-site scripting (XSS) vulnerability in Auto…6.1
- CVE-2024-5501The Supreme Modules Lite – Divi Theme, Extra Theme and Divi …6.4
- CVE-2024-55017Account Takeover in Corezoid 6.6.0 in the OAuth2 implementat…7.5
- CVE-2024-55019Incorrect access control in the component download_wb.cgi of…7.5
- CVE-2024-5502The Piotnet Addons For Elementor plugin for WordPress is vul…5.4
- CVE-2024-55020A command injection vulnerability in the DHCP activation fea…9.8
- CVE-2024-55021Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discov…7.5
- CVE-2024-55022Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discov…8.8
Are you affected by CVE-2024-55016?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
