SQL Injection Vulnerability in PHPGurukul Pre-School Enrollment System
CVE-2025-6323
6.9MEDIUM
What is CVE-2025-6323?
A vulnerability exists within the PHPGurukul Pre-School Enrollment System 1.0 that allows attackers to exploit the /enrollment.php file through improper handling of the 'fathername' argument. This flaw enables SQL injection, which could allow unauthorized users to execute malicious SQL queries remotely. It has been disclosed publicly, posing a significant risk as other parameters may also be vulnerable. Organizations using this software should take immediate precautions to mitigate potential exploits.
Affected Version(s)
Pre-School Enrollment System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.