PT-2025-9584 · Unknown · Phpgurukul Restaurant Table Booking System

Chenzi

+1

·

Publicado

2025-03-04

·

Atualizado

2025-03-04

·

CVE-2025-1900

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPGurukul Restaurant Table Booking System version 1.0
Description A critical issue was found in the system, affecting an unknown functionality of the file /add-table.php. The manipulation of the tableno argument leads to SQL injection. This issue can be exploited remotely.
Recommendations For PHPGurukul Restaurant Table Booking System version 1.0, consider restricting access to the /add-table.php file until a fix is available, and avoid using the tableno argument in this context to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-1900

Produtos afetados

Phpgurukul Restaurant Table Booking System