SQL Injection Vulnerability in PHPGurukul Vehicle Parking Management System
CVE-2025-7482
5.3MEDIUM
What is CVE-2025-7482?
The PHPGurukul Vehicle Parking Management System version 1.13 is vulnerable to a SQL injection attack caused by improper handling of user input in the /users/print.php file. An attacker can exploit this vulnerability remotely by manipulating the 'vid' argument, allowing unauthorized access to the database. Given that the details of this vulnerability have been publicly disclosed, it poses a significant risk to the security and integrity of user data. Prompt patching and mitigation strategies are strongly recommended.
Affected Version(s)
Vehicle Parking Management System 1.13
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.