SQL Injection Vulnerability in PHPGurukul Apartment Visitors Management System 1.0
CVE-2025-4554
What is CVE-2025-4554?
A SQL injection vulnerability exists in the PHPGurukul Apartment Visitors Management System 1.0, specifically in the /admin/bwdates-passreports-details.php file. The vulnerability arises from improper handling of the 'fromdate' and 'todate' parameters, allowing attackers to manipulate SQL queries and execute arbitrary commands. This can result in unauthorized access to sensitive data, potentially leading to data breaches. The issue can be exploited remotely, making it crucial for users to apply security measures promptly. The vulnerability has been disclosed to the public, heightening its potential for exploitation.
Affected Version(s)
Apartment Visitors Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved