PT-2025-18254 · Unknown · Phpgurukul Student Record System

Qkset

·

Published

2025-04-30

·

Updated

2025-05-14

·

CVE-2025-4112

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPGurukul Student Record System version 3.20
Description A critical issue was found in the PHPGurukul Student Record System. The vulnerability affects the file "add-course.php" and is related to the manipulation of the course-short argument, leading to SQL injection. The attack can be initiated remotely.
Recommendations For PHPGurukul Student Record System version 3.20, consider restricting access to the /add-course.php file until a patch is available. As a temporary workaround, avoid using the course-short argument in the affected file to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-4112

Affected Products

Phpgurukul Student Record System