Vulnerability CVE-2023-7099


Published: 2023-12-25

Description:
A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This issue affects some unknown processing of the file bwdates-report-result.php. The manipulation of the argument fromdate leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248951.

Type:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

 References:
https://vuldb.com/?id.248951
https://vuldb.com/?ctiid.248951
https://github.com/laoquanshi/heishou/blob/main/niv%20-SQL
https://github.com/laoquanshi/heishou/blob/main/sqlmap.png

Copyright 2026, cxsecurity.com

 

Back to Top