SQL Injection Vulnerability in PHPGurukul Vehicle Parking Management System
CVE-2025-7489
5.3MEDIUM
What is CVE-2025-7489?
A SQL injection vulnerability exists in the PHPGurukul Vehicle Parking Management System, specifically in the handling of the searchdata argument within the /admin/search-vehicle.php file. This security flaw allows remote attackers to potentially manipulate database queries, leading to unauthorized data access or manipulation. Exploitation of this vulnerability has been publicly disclosed, raising significant concerns for users of version 1.13 of the software.
Affected Version(s)
Vehicle Parking Management System 1.13
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.