SQL Injection Vulnerability in PHPGurukul Vehicle Parking Management System
CVE-2025-7520
What is CVE-2025-7520?
A vulnerability exists in PHPGurukul Vehicle Parking Management System version 1.13, specifically within the /admin/manage-category.php file. This flaw allows remote attackers to manipulate the 'del' argument, leading to a potential SQL injection. Exploiting this vulnerability could enable unauthorized access to sensitive data and manipulation of the application's database, highlighting the importance of ensuring proper input validation and sanitization mechanisms to safeguard against such attacks. The issue has been publicly disclosed, raising awareness about the security risks involved.
Affected Version(s)
Vehicle Parking Management System 1.13
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.