SQL Injection Vulnerability in PHPGurukul Art Gallery Management System
CVE-2025-6415
5.3MEDIUM
What is CVE-2025-6415?
A SQL injection vulnerability exists in PHPGurukul's Art Gallery Management System version 1.1, specifically within the file /admin/changeimage3.php. A flaw in the processing of the 'editid' argument allows attackers to execute arbitrary SQL queries, which could lead to unauthorized data access and manipulation. This exploitation can be initiated remotely, elevating the risk to users of this web application. The vulnerability has been made public, raising concerns about potential misuse.
Affected Version(s)
Art Gallery Management System 1.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.