PT-2025-9283 · Unknown · Phpgurukul News Portal

Panghuanjie66

·

Publicado

2025-03-03

·

Atualizado

2025-03-07

·

CVE-2025-1859

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPGurukul News Portal version 4.1
Description A critical issue has been found in the processing of the file /login.php, where the manipulation of the id argument leads to SQL injection. This issue can be exploited remotely.
Recommendations For PHPGurukul News Portal version 4.1, consider restricting access to the /login.php file until a fix is available, and avoid using the id argument in this context to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-1859

Produtos afetados

Phpgurukul News Portal