PT-2025-24344 · Unknown · Phpgurukul Employee Record Management System

F1Rstb100D

·

Published

2025-06-07

·

Updated

2025-06-10

·

CVE-2025-5838

CVSS v3.1
8.8
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPGurukul Employee Record Management System version 1.3
Description A critical vulnerability was found in the PHPGurukul Employee Record Management System. The issue affects an unknown functionality of the file /admin/adminprofile.php. The manipulation of the
AdminName
argument leads to SQL injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Recommendations For PHPGurukul Employee Record Management System version 1.3, consider disabling the
AdminName
argument in the /admin/adminprofile.php file until a patch is available to prevent SQL injection attacks. Restrict access to the /admin/adminprofile.php file to minimize the risk of exploitation. Avoid using the
AdminName
argument in the affected file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-5838

Affected Products

Phpgurukul Employee Record Management System