SQL Injection Vulnerability in PHPGurukul Human Metapneumovirus Testing Management System
CVE-2025-5694
What is CVE-2025-5694?
A security flaw has been identified in the PHPGurukul Human Metapneumovirus Testing Management System 1.0, specifically within the /search-report-result.php file. By manipulating the 'serachdata' parameter, potential attackers can execute unauthorized SQL queries, compromising the database integrity. This vulnerability can be exploited remotely, exposing sensitive information and affecting the system's overall security. It is crucial for users and administrators to be aware of this issue and apply necessary mitigations to safeguard their systems.
Affected Version(s)
Human Metapneumovirus Testing Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.