SQL Injection Vulnerability in PHPGurukul Pre-School Enrollment System
CVE-2025-6320
5.3MEDIUM
What is CVE-2025-6320?
The PHPGurukul Pre-School Enrollment System version 1.0 is exposed to a SQL injection vulnerability located in the /admin/add-class.php file. This vulnerability arises when an attacker manipulates the argument 'classname', which can lead to unauthorized access to the underlying database. Such a flaw not only permits remote exploitation but also poses a significant risk as it has been publicly disclosed, making affected systems susceptible to exploitation by malicious actors.
Affected Version(s)
Pre-School Enrollment System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.