PT-2025-18369 · Unknown · Phpgurukul Park Ticketing Management System

Yl525

·

Published

2025-05-01

·

Updated

2025-05-01

·

CVE-2025-4153

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPGurukul Park Ticketing Management System version 2.0
Description A critical vulnerability was found in the PHPGurukul Park Ticketing Management System. The issue affects an unknown functionality of the file /profile.php, where the manipulation of the adminname argument leads to SQL injection. This attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations For PHPGurukul Park Ticketing Management System version 2.0, consider disabling the /profile.php file or restricting access to it until a patch is available. As a temporary workaround, avoid using the adminname argument in the /profile.php file to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-4153

Affected Products

Phpgurukul Park Ticketing Management System