SQL Injection Vulnerability in PHPGurukul User Management System
CVE-2025-2050
What is CVE-2025-2050?
A vulnerability exists in the PHPGurukul User Registration & Login and User Management System version 3.3, specifically affecting the /login.php file. The issue arises from improper handling of the email parameter, which can be manipulated to execute SQL injection attacks. This vulnerability allows attackers to exploit the system remotely, potentially gaining unauthorized access to sensitive data. The exploit has been publicly disclosed, making it crucial for users and administrators to take immediate action to secure their systems.
Affected Version(s)
User Registration & Login and User Management System 3.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.