PT-2025-35848 · Phpgurukul · Phpgurukul Beauty Parlour Management System
Xiaoxin
·
Published
2025-09-03
·
Updated
2025-09-04
·
CVE-2025-9932
Xiaoxin
·
Published
2025-09-03
·
Updated
2025-09-04
·
CVE-2025-9932
7.5
High
Base vector | Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
PHPGurukul Beauty Parlour Management System version 1.1
Description:
A flaw exists in PHPGurukul Beauty Parlour Management System 1.1 within the file `/admin/update-image.php`. Manipulation of the `lid` argument can lead to SQL injection, potentially allowing for remote attacks. The exploit for this issue has been published.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Special Elements Injection
SQL injection