CVE-2024-5065
published 2024-05-17CVE-2024-5065: A vulnerability classified as critical has been found in PHPGurukul Online Course Registration System 3.1. Affected is an unknown function of the file…
PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.70%
48.7th percentile
A vulnerability classified as critical has been found in PHPGurukul Online Course Registration System 3.1. Affected is an unknown function of the file /onlinecourse/. The manipulation of the argument regno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264924.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome_chrome | — | — | |
| phpgurukul | online_course_registration_system | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-454p-4wfm-4wpx: A vulnerability classified as critical has been found in PHPGurukul Online Course Registration System 3
ghsa_unreviewed·2024-05-17
CVE-2024-5065 [HIGH] CWE-89 GHSA-454p-4wfm-4wpx: A vulnerability classified as critical has been found in PHPGurukul Online Course Registration System 3
A vulnerability classified as critical has been found in PHPGurukul Online Course Registration System 3.1. Affected is an unknown function of the file /onlinecourse/. The manipulation of the argument regno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264924.
Chrome
Stable Channel Update for Desktop: CVE-2025-5065
vendor_chrome·2025-05-27·CVSS 6.5
CVE-2025-5065 [MEDIUM] Stable Channel Update for Desktop: CVE-2025-5065
Stable Channel Update for Desktop
CVE-2025-5065: Inappropriate implementation in FileSystemAccess API. Reported by NDevTK on 2022-03-11 [$1000][ 356658477 ] Medium CVE-2025-5066: Inappropriate implementation in Messages
Reported by Mohit Raj (shadow2639) on 2024-07-31 [TBD][ 417215501 ] Medium CVE-2025-5281: Inappropriate implementation in BFCache
Severity: medium
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-26961 kernel: mac802154: fix llsec key resources release in mac802154_llsec_key_del
bugzilla·2024-05-01·CVSS 7.8
CVE-2024-26961 [HIGH] CVE-2024-26961 kernel: mac802154: fix llsec key resources release in mac802154_llsec_key_del
CVE-2024-26961 kernel: mac802154: fix llsec key resources release in mac802154_llsec_key_del
In the Linux kernel, the following vulnerability has been resolved:
mac802154: fix llsec key resources release in mac802154_llsec_key_del
The Linux kernel CVE team has assigned CVE-2024-26961 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050129-CVE-2024-26961-408d@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278177]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
Via RHSA-2024:5065 https://access.redha
Bugzilla
CVE-2024-26870 kernel: NFSv4.2: fix nfs4_listxattr kernel BUG at mm/usercopy.c:102
bugzilla·2024-04-17·CVSS 5.5
CVE-2024-26870 [MEDIUM] CVE-2024-26870 kernel: NFSv4.2: fix nfs4_listxattr kernel BUG at mm/usercopy.c:102
CVE-2024-26870 kernel: NFSv4.2: fix nfs4_listxattr kernel BUG at mm/usercopy.c:102
In the Linux kernel, the following vulnerability has been resolved:
NFSv4.2: fix nfs4_listxattr kernel BUG at mm/usercopy.c:102
The Linux kernel CVE team has assigned CVE-2024-26870 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041738-CVE-2024-26870-7aea@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2275712]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
Via RHSA-2024:5065 https://access.redhat.com/errata/RHSA-20
Bugzilla
CVE-2024-26640 kernel: tcp: add sanity checks to rx zerocopy
bugzilla·2024-03-18·CVSS 5.5
CVE-2024-26640 [MEDIUM] CVE-2024-26640 kernel: tcp: add sanity checks to rx zerocopy
CVE-2024-26640 kernel: tcp: add sanity checks to rx zerocopy
In the Linux kernel, the following vulnerability has been resolved:
tcp: add sanity checks to rx zerocopy
The Linux kernel CVE team has assigned CVE-2024-26640 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/[email protected]/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2270101]
---
This was fixed for Fedora with the 6.7.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
Via RHSA-2024:5065 https://acc
https://github.com/BurakSevben/CVEs/blob/main/Online%20Course%20Registration%20System/Online%20Course%20Registration%20System%20-%20SQL%20Injection%20-%203%20(Unauthenticated).mdhttps://vuldb.com/?ctiid.264924https://vuldb.com/?id.264924https://vuldb.com/?submit.336239https://github.com/BurakSevben/CVEs/blob/main/Online%20Course%20Registration%20System/Online%20Course%20Registration%20System%20-%20SQL%20Injection%20-%203%20(Unauthenticated).mdhttps://vuldb.com/?ctiid.264924https://vuldb.com/?id.264924https://vuldb.com/?submit.336239
2024-05-17
Published