SQL Injection Vulnerability in PHPGurukul Credit Card Application Management System
CVE-2025-4941
What is CVE-2025-4941?
A security vulnerability exists in the PHPGurukul Credit Card Application Management System 1.0 due to improper handling of user inputs in the /admin/index.php file. An attacker can exploit this vulnerability by manipulating the Username argument, which can lead to unauthorized SQL queries being executed within the database. This remote attack vector could compromise sensitive financial data and user accounts. The exploit has been publicly disclosed, raising the urgency for affected users to apply necessary safeguards and updates to their systems.
Affected Version(s)
Credit Card Application Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved