CVE-2023-3275: PHPGurukul Rail Pass Management System POST Request view-pass-detail.php sql injection

6.3 CVSS

Description

A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view-pass-detail.php of the component POST Request Handler. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The identifier VDB-231625 was assigned to this vulnerability. In PHPGurukul Rail Pass Management System 1.0 wurde eine kritische Schwachstelle entdeckt. Es geht um eine nicht näher bekannte Funktion der Datei /view-pass-detail.php der Komponente POST Request Handler. Durch das Beeinflussen des Arguments searchdata mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen.

Classification

CVE ID: CVE-2023-3275

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.3

Affected Products

Vendor: PHPGurukul

Product: Rail Pass Management System

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.31% (probability of being exploited)

EPSS Percentile: 70.14% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://vuldb.com/?id.231625
https://vuldb.com/?ctiid.231625

Timeline