A vulnerability was found in PHPGurukul Medical Card Generation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/card-bwdates-reports-details.php of the component Report of Medical Card Page. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
                
            References
                    | Link | Resource | 
|---|---|
| https://phpgurukul.com/ | Product | 
| https://vuldb.com/?ctiid.281563 | Permissions Required VDB Entry | 
| https://vuldb.com/?id.281563 | Permissions Required VDB Entry | 
| https://vuldb.com/?submit.427400 | Third Party Advisory VDB Entry | 
Configurations
                    History
                    16 Jul 2025, 17:37
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : 5.8
         v3 : 4.7  | 
| First Time | 
        
        Phpgurukul medical Card Generation System
         Phpgurukul  | 
|
| CPE | cpe:2.3:a:phpgurukul:medical_card_generation_system:1.0:*:*:*:*:*:*:* | 
30 Oct 2024, 15:13
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : 5.8
         v3 : 7.2  | 
| First Time | 
        
        Anujkumar medical Card Generation System
         Anujkumar  | 
|
| CPE | cpe:2.3:a:anujkumar:medical_card_generation_system:1.0:*:*:*:*:*:*:* | |
| References | () https://phpgurukul.com/ - Product | |
| References | () https://vuldb.com/?ctiid.281563 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.281563 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?submit.427400 - Third Party Advisory, VDB Entry | 
25 Oct 2024, 12:56
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
        
        
  | 
23 Oct 2024, 17:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-10-23 17:15
Updated : 2025-07-16 17:37
NVD link : CVE-2024-10296
Mitre link : CVE-2024-10296
CVE.ORG link : CVE-2024-10296
JSON object : View
Products Affected
                phpgurukul
- medical_card_generation_system
 
CWE
                
                    
                        
                        CWE-89
                        
            Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
