PT-2025-53593 · Unknown · Krishanmuraiji Sms

Kabir0104K

·

Published

2025-12-26

·

Updated

2025-12-31

·

CVE-2025-66947

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions krishanmuraiji SMS version 1.0
Description A SQL injection issue exists in krishanmuraiji SMS version 1.0. The issue is located within the '/studentms/admin/edit-class-detail.php' file and is triggered through the editid GET parameter. An attacker can use SQL SLEEP() to cause controlled delays and extract database information. Exploitation could result in complete database compromise, particularly within the administrative module.
Recommendations Apply a fix for krishanmuraiji SMS version 1.0 to address the SQL injection issue in the '/studentms/admin/edit-class-detail.php' file. As a temporary workaround, restrict access to the /studentms/admin/edit-class-detail.php file. Sanitize the editid GET parameter to prevent SQL injection attacks.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66947

Affected Products

Krishanmuraiji Sms