SQL Injection Vulnerability in PHPGurukul Curfew e-Pass Management System
CVE-2025-5561
6.9MEDIUM
What is CVE-2025-5561?
A SQL injection vulnerability exists in the PHPGurukul Curfew e-Pass Management System 1.0, specifically within the /admin/view-pass-detail.php file. The vulnerability arises from improper handling of the 'viewid' parameter, which can be exploited to manipulate SQL queries. Attackers can trigger this vulnerability remotely, allowing potential unauthorized access to the system or exposure of sensitive data. It is crucial for users to apply necessary patches and security measures to mitigate risks associated with this vulnerability.
Affected Version(s)
Curfew e-Pass Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.