PT-2025-47082 · Phpgurukul · Phpgurukul Tourism Management System

Littlewhite

·

Published

2025-11-16

·

Updated

2025-11-21

·

CVE-2025-13247

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPGurukul Tourism Management System version 1.0
Description A security flaw exists in PHPGurukul Tourism Management System 1.0. The issue is related to SQL injection within an unknown function of the file /admin/user-bookings.php. Manipulation of the uid argument can trigger the injection. The attack can be launched remotely, and an exploit has been publicly released.
Recommendations Apply any available updates or patches for the software. As a temporary workaround, restrict access to the /admin/user-bookings.php file. Sanitize the uid input to prevent SQL injection attacks.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-13247

Affected Products

Phpgurukul Tourism Management System