SQL Injection Vulnerability in PHPGurukul Online Nurse Hiring System
CVE-2025-1581
Key Information:
- Vendor
- PHPgurukul
- Vendor
- CVE Published:
- 23 February 2025
Badges
Summary
A SQL injection vulnerability exists in the PHPGurukul Online Nurse Hiring System 1.0, specifically within the /book-nurse.php?bookid=1 file. The flaw arises from improper handling of the 'contactname' parameter, allowing attackers to manipulate SQL queries. This vulnerability can be exploited remotely, exposing sensitive information and potentially leading to further compromise of the application. The exploit has been made public, emphasizing the need for immediate mitigation strategies.
Affected Version(s)
Online Nurse Hiring System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved