PT-2025-53593 · Unknown · Krishanmuraiji Sms
Kabir0104K
·
Published
2025-12-26
·
Updated
2025-12-31
·
CVE-2025-66947
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
krishanmuraiji SMS version 1.0
Description
A SQL injection issue exists in krishanmuraiji SMS version 1.0. The issue is located within the '/studentms/admin/edit-class-detail.php' file and is triggered through the
editid GET parameter. An attacker can use SQL SLEEP() to cause controlled delays and extract database information. Exploitation could result in complete database compromise, particularly within the administrative module.Recommendations
Apply a fix for krishanmuraiji SMS version 1.0 to address the SQL injection issue in the '/studentms/admin/edit-class-detail.php' file. As a temporary workaround, restrict access to the
/studentms/admin/edit-class-detail.php file. Sanitize the editid GET parameter to prevent SQL injection attacks.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Krishanmuraiji Sms