PT-2025-21875 · Unknown · Phpgurukul Notice Board System

Wangzhizheng

·

Published

2025-05-19

·

Updated

2025-05-24

·

CVE-2025-4906

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: PHPGurukul Notice Board System version 1.0
Description: A critical issue was found in the PHPGurukul Notice Board System. The problem is related to the manipulation of the Username argument, which leads to SQL injection. This can be exploited remotely.
Recommendations: For PHPGurukul Notice Board System version 1.0, consider restricting access to the /login.php file until a patch is available. As a temporary workaround, avoid using the Username parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-4906

Affected Products

Phpgurukul Notice Board System