SQL Injection Vulnerability in PHPGurukul Online Nurse Hiring System 1.0
CVE-2025-1583
Key Information:
- Vendor
- PHPgurukul
- Vendor
- CVE Published:
- 23 February 2025
Badges
Summary
The PHPGurukul Online Nurse Hiring System 1.0 is susceptible to SQL injection due to improper handling of user input in the /admin/search-report-details.php file. By manipulating the 'searchinput' argument, an attacker can execute arbitrary SQL commands against the database, potentially compromising sensitive data. This vulnerability can be exploited remotely, making it a significant risk for installations of this system. Users are urged to take immediate precautions to mitigate the threat.
Affected Version(s)
Online Nurse Hiring System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved