SQL Injection Vulnerability in PHPGurukul Pre-School Enrollment System
CVE-2025-4154
Summary
A security flaw exists in the PHPGurukul Pre-School Enrollment System version 1.0 within the /admin/enrollment-details.php file. This vulnerability arises from improper handling of the 'Status' argument, allowing for SQL injection attacks. Threat actors can exploit this weakness remotely, manipulating the database by executing arbitrary SQL code. The public disclosure of this exploit means it may already be under active attack, necessitating immediate action to secure the affected system.
Affected Version(s)
Pre-School Enrollment System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved