PT-2025-18276 · Unknown · Phpgurukul Park Ticketing Management System

Published

2025-04-30

·

Updated

2025-04-30

·

CVE-2025-45018

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPGurukul Park Ticketing Management System version 2.0
Description A SQL injection issue was discovered in the foreigner-bwdates-reports-details.php file. This issue allows remote attackers to execute arbitrary SQL code via the todate parameter.
Recommendations For PHPGurukul Park Ticketing Management System version 2.0, consider restricting access to the foreigner-bwdates-reports-details.php file until a patch is available. As a temporary workaround, avoid using the todate parameter in the affected file to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-45018

Affected Products

Phpgurukul Park Ticketing Management System