Time-Based Blind SQL Injection Vulnerability in PHPGurukul Dairy Farm Shop Management System
CVE-2025-51672

8HIGH

Key Information:

Vendor

PHPGurukul

Vendor
CVE Published:
26 June 2025

What is CVE-2025-51672?

A time-based blind SQL injection vulnerability has been identified in the PHPGurukul Dairy Farm Shop Management System version 1.3. This vulnerability resides in the manage-companies.php file, where attackers can exploit improper validation of the companyname parameter in a POST request. By crafting a malicious query, remote attackers can execute arbitrary SQL commands, potentially compromising sensitive user data and the integrity of the database. It is crucial for users of this system to apply security patches to mitigate this risk.

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.