SQL Injection Vulnerability in PHPGurukul Notice Board System by PHPGurukul
CVE-2025-5566
5.3MEDIUM
Key Information:
- Vendor
PHPgurukul
- Status
- Vendor
- CVE Published:
- 4 June 2025
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2025-5566?
A vulnerability has been identified in PHPGurukul Notice Board System version 1.0, specifically in the /search-notice.php file. The flaw arises through improper handling of the 'searchdata' parameter, allowing an attacker to perform SQL injection. This security loophole permits a remote attacker to engage in unauthorized actions which could compromise the database's integrity and confidentiality. Public knowledge of the exploit poses a significant risk.
Affected Version(s)
Notice Board System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.