SQL Injection in PHPGurukul Online Library Management System 3.0
CVE-2025-7600
5.3MEDIUM
What is CVE-2025-7600?
A vulnerability in the PHPGurukul Online Library Management System version 3.0 allows for SQL injection via manipulation of the 'stid' parameter in the '/admin/student-history.php' file. This weakness enables attackers to execute arbitrary SQL commands, potentially leading to unauthorized data access or manipulation. As the exploit can be initiated remotely, it poses a significant security risk. The vulnerability has been publicly disclosed, highlighting the need for immediate remediation.
Affected Version(s)
Online Library Management System 3.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.