SQL Injection Vulnerability in PHPGurukul Dairy Farm Shop Management System
CVE-2025-51671

5.4MEDIUM

Key Information:

Vendor

PHPGurukul

Vendor
CVE Published:
26 June 2025

What is CVE-2025-51671?

A SQL injection flaw has been identified in PHPGurukul's Dairy Farm Shop Management System version 1.3, enabling remote attackers to manipulate SQL queries. This vulnerability allows the execution of arbitrary SQL commands through the category and categorycode parameters in a POST request directed at manage-categories.php, posing a significant risk to database integrity and confidentiality.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-51671 : SQL Injection Vulnerability in PHPGurukul Dairy Farm Shop Management System