SQL Injection Vulnerability in Complaint Management System by phpgurukul
CVE-2025-57147

7.5HIGH

Key Information:

Vendor

phpgurukul

Vendor
CVE Published:
3 September 2025

What is CVE-2025-57147?

A SQL Injection vulnerability has been identified in phpgurukul's Complaint Management System version 2.0. This security flaw arises from inadequate input validation of several key parameters, including fullname, email, and contact number within the user registration functionality (user/registration.php). Exploitation of this vulnerability could allow an attacker to execute arbitrary SQL commands, potentially compromising the application's database integrity and exposing sensitive user information.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.