SQL Injection Vulnerability in PHPGurukul BP Monitoring Management System
CVE-2025-8134
What is CVE-2025-8134?
The PHPGurukul BP Monitoring Management System version 1.0 is susceptible to an SQL injection vulnerability through the manipulation of the 'fromdate' and 'todate' parameters in the /bwdates-report-result.php file. This flaw allows attackers to execute unauthorized SQL commands remotely, potentially leading to unauthorized access or data manipulation. The public disclosure of the exploit highlights the urgent need for users of this software to apply security measures to mitigate the risk of this vulnerability.
Affected Version(s)
BP Monitoring Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved