SQL Injection Vulnerability in PHPGurukul Student Record System 3.2
CVE-2025-6915
Key Information:
- Vendor
PHPgurukul
- Status
- Vendor
- CVE Published:
- 30 June 2025
Badges
What is CVE-2025-6915?
A vulnerability has been identified in PHPGurukul Student Record System 3.2, specifically related to the '/register.php' file. The flaw occurs due to improper validation of the 'session' argument, allowing for SQL injection attacks. This can potentially enable remote attackers to manipulate the underlying database, leading to unauthorized data exposure and manipulation. The exploit is publicly disclosed, raising concerns about its potential misuse. Organizations using the affected product are strongly advised to assess their systems and implement necessary security measures to protect against exploitation.
Affected Version(s)
Student Record System 3.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.