← Vulnerability feed

Vulnerability record · CVE-2024-0355 · published 10 January 2024

CVE-2024-0355: Phpgurukul dairy farm shop management system sql injection vulnerability

Phpgurukul · Dairy Farm Shop Management System

A vulnerability, which was classified as critical, was found in PHPGurukul Dairy Farm Shop Management System up to 1.1. Affected is an unknown function of the file add-category.php. The manipulation of the argument category leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-250122 is the identifier assigned to this vulnerability.

9.8 CVSS 3.1 Critical EPSS 0.70% · top 48.9% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 5.2
0.70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability, which was classified as critical, was found in PHPGurukul Dairy Farm Shop Management System up to 1.1. Affected is an unknown function of the file add-category.php. The manipulation of the argument category leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-250122 is the identifier assigned to this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://medium.com/@heishou/dfsms-has-sql-injection-vulnerability-e9cfbc375be8 ExploitThird Party Advisory
https://vuldb.com/?ctiid.250122 Permissions RequiredThird Party Advisory
https://vuldb.com/?id.250122 Third Party Advisory
https://medium.com/@heishou/dfsms-has-sql-injection-vulnerability-e9cfbc375be8 ExploitThird Party Advisory
https://vuldb.com/?ctiid.250122 Permissions RequiredThird Party Advisory
https://vuldb.com/?id.250122 Third Party Advisory

Track CVE-2024-0355 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-40943Phpgurukul dairy farm shop management system sql injection vulnerabilityDairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.EPSS 1.1%9.8CVE-2022-40944Phpgurukul dairy farm shop management system sql injection vulnerabilityDairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file.EPSS 1.2%9.8CVE-2022-29007Phpgurukul dairy farm shop management system sql injection vulnerabilityMultiple SQL injection vulnerabilities via the username and password parameters in the Admin panel of Dairy Farm Shop Management System v1.0 allows a…EPSS 19%9.8CVE-2020-36062Phpgurukul dairy farm shop management system hard-coded credentials vulnerabilityDairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the contro…EPSS 2.3%9.8CVE-2020-5307Phpgurukul dairy farm shop management system sql injection vulnerabilityPHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category…EPSS 16%8.0CVE-2025-51672Phpgurukul dairy farm shop management system sql injection vulnerabilityA time-based blind SQL injection vulnerability was identified in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability exists in th…EPSS 0.41%7.5CVE-2023-41594Phpgurukul dairy farm shop management system sql injection vulnerabilityDairy Farm Shop Management System Using PHP and MySQL v1.1 was discovered to contain multiple SQL injection vulnerabilities in the Login function via…EPSS 0.96%6.9CVE-2025-5578Phpgurukul dairy farm shop management system injection vulnerabilityA vulnerability has been found in PHPGurukul Dairy Farm Shop Management System 1.3 and classified as critical. Affected by this vulnerability is an u…EPSS 0.79%

Source: NIST National Vulnerability Database (record CVE-2024-0355), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.