PT-2025-14820 · Unknown · Phpgurukul E-Diary Management System

Loki.T

·

Published

2025-04-04

·

Updated

2025-04-09

·

CVE-2025-3188

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPGurukul e-Diary Management System version 1.0
Description A critical issue has been discovered in the /add-notes.php file, where manipulation of the Category argument leads to SQL injection. The attack can be initiated remotely. An exploit has been publicly disclosed and may be utilized.
Recommendations For PHPGurukul e-Diary Management System version 1.0, consider disabling the /add-notes.php file or restricting access to it until a patch is available. Avoid using the Category argument in the affected file to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-3188

Affected Products

Phpgurukul E-Diary Management System