PT-2025-18277 · Unknown · Phpgurukul Park Ticketing Management System

Published

2025-04-30

·

Updated

2025-04-30

·

CVE-2025-45019

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPGurukul Park Ticketing Management System version 2.0
Description A SQL injection issue was found in the /add-foreigners-ticket.php file. This allows remote attackers to execute arbitrary code via the cprice POST request parameter.
Recommendations For PHPGurukul Park Ticketing Management System version 2.0, consider disabling the cprice parameter in the /add-foreigners-ticket.php file until a patch is available. Restrict access to the /add-foreigners-ticket.php file to minimize the risk of exploitation. Avoid using the cprice parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-45019

Affected Products

Phpgurukul Park Ticketing Management System