SQL Injection Vulnerability in Phpgurukul Cyber Cafe Management System
CVE-2025-70892
9.8CRITICAL
Key Information:
- Vendor
PhpGurukul
- Vendor
- CVE Published:
- 15 January 2026
What is CVE-2025-70892?
The Cyber Cafe Management System by Phpgurukul, version 1.0, is susceptible to a SQL Injection vulnerability within its user management module. This flaw arises from inadequate validation of user-supplied input in the username parameter found in the add-users.php endpoint, allowing attackers to manipulate database queries. By exploiting this vulnerability, unauthorized access to sensitive data may be achieved, highlighting the need for immediate remediation and improved validation mechanisms.
