CVE-2024-5066
published 2024-05-17CVE-2024-5066: A vulnerability classified as critical was found in PHPGurukul Online Course Registration System 3.1. Affected by this vulnerability is an unknown…
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.57%
43.4th percentile
A vulnerability classified as critical was found in PHPGurukul Online Course Registration System 3.1. Affected by this vulnerability is an unknown functionality of the file /pincode-verification.php. The manipulation of the argument pincode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264925 was assigned to this vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome_chrome | — | — | |
| phpgurukul | online_course_registration_system | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4g6g-5g88-76v5: A vulnerability classified as critical was found in PHPGurukul Online Course Registration System 3
ghsa_unreviewed·2024-05-17
CVE-2024-5066 [MEDIUM] CWE-89 GHSA-4g6g-5g88-76v5: A vulnerability classified as critical was found in PHPGurukul Online Course Registration System 3
A vulnerability classified as critical was found in PHPGurukul Online Course Registration System 3.1. Affected by this vulnerability is an unknown functionality of the file /pincode-verification.php. The manipulation of the argument pincode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264925 was assigned to this vulnerability.
Chrome
Stable Channel Update for Desktop: CVE-2025-5065
vendor_chrome·2025-05-27·CVSS 6.5
CVE-2025-5065 [MEDIUM] Stable Channel Update for Desktop: CVE-2025-5065
Stable Channel Update for Desktop
CVE-2025-5065: Inappropriate implementation in FileSystemAccess API. Reported by NDevTK on 2022-03-11 [$1000][ 356658477 ] Medium CVE-2025-5066: Inappropriate implementation in Messages
Reported by Mohit Raj (shadow2639) on 2024-07-31 [TBD][ 417215501 ] Medium CVE-2025-5281: Inappropriate implementation in BFCache
Severity: medium
Chrome
Early Stable Update for Desktop: CVE-2025-5066
vendor_chrome·2025-05-21·CVSS 6.5
CVE-2025-5066 [MEDIUM] Early Stable Update for Desktop: CVE-2025-5066
Early Stable Update for Desktop
CVE-2025-5066: Inappropriate implementation in Messages. Reported by Mohit Raj (shadow2639) on 2024-07-31 [$500][ 40075024 ] Low CVE-2025-5067: Inappropriate implementation in Tab Strip
Reported by Khalil Zhani on 2023-10-17 We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel
Severity: medium
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-27062 kernel: nouveau: lock the client object tree.
bugzilla·2024-05-01·CVSS 5.5
CVE-2024-27062 [MEDIUM] CVE-2024-27062 kernel: nouveau: lock the client object tree.
CVE-2024-27062 kernel: nouveau: lock the client object tree.
In the Linux kernel, the following vulnerability has been resolved:
nouveau: lock the client object tree.
The Linux kernel CVE team has assigned CVE-2024-27062 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050130-CVE-2024-27062-3291@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278388]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Support
Via RHSA-2024:5067 https://access.redhat.com/errata/RHSA-2024:5067
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Support
Via RHSA-2024:5066 https://access.redhat.com/errata/RHSA-2024
Bugzilla
CVE-2024-26930 kernel: scsi: qla2xxx: Fix double free of the ha->vp_map pointer
bugzilla·2024-05-01·CVSS 7.8
CVE-2024-26930 [HIGH] CVE-2024-26930 kernel: scsi: qla2xxx: Fix double free of the ha->vp_map pointer
CVE-2024-26930 kernel: scsi: qla2xxx: Fix double free of the ha->vp_map pointer
In the Linux kernel, the following vulnerability has been resolved:
scsi: qla2xxx: Fix double free of the ha->vp_map pointer
The Linux kernel CVE team has assigned CVE-2024-26930 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050122-CVE-2024-26930-4f3e@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278249]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Support
Via RHSA-2024:5067 https://access.redhat.com/errata/RHSA-2024:5067
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Support
Via RHSA-2024:5066 http
Bugzilla
CVE-2022-48637 kernel: bnxt: prevent skb UAF after handing over to PTP worker
bugzilla·2024-04-29·CVSS 7.8
CVE-2022-48637 [HIGH] CVE-2022-48637 kernel: bnxt: prevent skb UAF after handing over to PTP worker
CVE-2022-48637 kernel: bnxt: prevent skb UAF after handing over to PTP worker
In the Linux kernel, the following vulnerability has been resolved:
bnxt: prevent skb UAF after handing over to PTP worker
The Linux kernel CVE team has assigned CVE-2022-48637 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024042855-CVE-2022-48637-d149@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Support
Via RHSA-2024:5067 https://access.redhat.com/errata/RHSA-2024:5067
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.2 Extended Update Support
Via RHSA-2024:5066 https://access.redhat.com/errata/RHSA-2024:5066
---
This issue has been addressed in the fol
https://github.com/BurakSevben/CVEs/blob/main/Online%20Course%20Registration%20System/Online%20Course%20Registration%20System%20-%20SQL%20Injection%20-%204.mdhttps://vuldb.com/?ctiid.264925https://vuldb.com/?id.264925https://vuldb.com/?submit.336240https://github.com/BurakSevben/CVEs/blob/main/Online%20Course%20Registration%20System/Online%20Course%20Registration%20System%20-%20SQL%20Injection%20-%204.mdhttps://vuldb.com/?ctiid.264925https://vuldb.com/?id.264925https://vuldb.com/?submit.336240
2024-05-17
Published