Executive brief
PHPGurukul Online Course Registration is a web application used to manage student enrollments and course data. A security flaw allows remote attackers to interfere with the application's database without needing a username or password. This could lead to the theft of sensitive student information, unauthorized modification of records, or disruption of the registration service.
Technical details
A SQL injection vulnerability exists in PHPGurukul Online Course Registration 3.1 within the '/admin/check_availability.php' file. The root cause is the failure to sanitize or validate the 'regno' POST parameter before using it in a database query. An unauthenticated remote attacker can exploit this using boolean-based or time-based blind SQL injection techniques. Successful exploitation allows for unauthorized database access, potentially leading to data exfiltration, modification, or full system compromise. A public exploit (PoC) has been disclosed, and no official patch is currently documented in the advisory.
Affected products
- PHPGurukul Online Course Registration 3.1
Timeline
- 2026-03-25: disclosed: Public issue opened on GitHub with PoC details
- 2026-04-09: advisory: NVD publication date