
CVE-2025-1902 – PHPGurukul Student Record System password-recovery.php sql injection
https://notcve.org/view.php?id=CVE-2025-1902
04 Mar 2025 — A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability affects unknown code of the file /password-recovery.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. • https://github.com/panghuanjie/Code-audits/issues/3 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-3771 – PHPGurukul Student Record System edit-subject.php sql injection
https://notcve.org/view.php?id=CVE-2024-3771
15 Apr 2024 — A vulnerability was found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this issue is some unknown functionality of the file /edit-subject.php. The manipulation of the argument sub1/sub2/sub3/sub4/udate leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/BurakSevben/CVEs/blob/main/Student%20Record%20System%203.20/Student%20Record%20System%20-%20SQL%20Injection%20-%204.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-3770 – PHPGurukul Student Record System sql injection
https://notcve.org/view.php?id=CVE-2024-3770
15 Apr 2024 — A vulnerability has been found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manage-courses.php?del=1. The manipulation of the argument del leads to sql injection. The attack can be launched remotely. • https://github.com/BurakSevben/CVEs/blob/main/Student%20Record%20System%203.20/Student%20Record%20System%20-%20SQL%20Injection%20-%203.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-3769 – PHPGurukul Student Record System login.php sql injection
https://notcve.org/view.php?id=CVE-2024-3769
15 Apr 2024 — A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an unknown function of the file /login.php. The manipulation of the argument id/password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/BurakSevben/CVEs/blob/main/Student%20Record%20System%203.20/Student%20Record%20System%20-%20Authentication%20Bypass.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2021-26764
https://notcve.org/view.php?id=CVE-2021-26764
22 Jul 2021 — SQL injection vulnerability in PHPGurukul Student Record System v 4.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit-std.php. Una vulnerabilidad de inyección SQL en PHPGurukul Student Record System versión v4.0 permite a atacantes remotos ejecutar sentencias SQL arbitrarias, por medio del parámetro id del archivo edit-std.php • https://github.com/BigTiger2020/Student-Record-System-/blob/main/README.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2021-26762
https://notcve.org/view.php?id=CVE-2021-26762
22 Jul 2021 — SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the cid parameter to edit-course.php. Una vulnerabilidad de inyección SQL en PHPGurukul Student Record System versión 4.0, permite a atacantes remotos ejecutar sentencias SQL arbitrarias, por medio del parámetro cid del archivo edit-course.php • https://phpgurukul.com • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2021-26765
https://notcve.org/view.php?id=CVE-2021-26765
22 Jul 2021 — SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid parameter to edit-sub.php. Una vulnerabilidad de inyección SQL en PHPGurukul Student Record System versión 4.0, permite a atacantes remotos ejecutar sentencias SQL arbitrarias, por medio del parámetro sid del archivo edit-sub.php • https://github.com/BigTiger2020/Student-Record-System-/blob/main/README.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •