SQL Injection Vulnerability in PHPGurukul Pre-School Enrollment System
CVE-2025-4110
Key Information:
- Vendor
- PHPgurukul
- Vendor
- CVE Published:
- 30 April 2025
Badges
Summary
A vulnerability exists within the PHPGurukul Pre-School Enrollment System 1.0, specifically in the '/admin/edit-teacher.php' file. The vulnerability is exploited through an unsanitized input parameter 'mobilenumber', allowing remote attackers to manipulate SQL queries. This opens the system to potential data breaches and unauthorized access, as the exploit may affect other parameters as well. Given the public disclosure of this vulnerability, immediate attention and patching are recommended to mitigate the risks.
Affected Version(s)
Pre-School Enrollment System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved