vendor:
User Registration & Login and User Management System
by:
Ashutosh Singh Umath
8.1
CVSS
HIGH
SQL Injection
89
CWE
Product Name: User Registration & Login and User Management System
Affected Version From: 3
Affected Version To: 3
Patch Exists: NO
Related CWE: Requested
CPE: a:phpgurukul:user_registration_login_and_user_management_system:3.0
Platforms Tested: Windows 11
2023
User Registration & Login and User Management System v3.0 – SQL Injection (Unauthenticated)
The User Registration & Login and User Management System v3.0 is vulnerable to SQL Injection. An attacker can exploit this vulnerability to gain unauthorized access to the admin portal and download all the data from the database.
Mitigation:
The vendor should sanitize user input and use parameterized queries to prevent SQL Injection attacks. Regular security audits and code reviews should be conducted to identify and fix any potential vulnerabilities.