7.2
CVSSv3

CVE-2025-25354

CVSSv4: NA | CVSSv3: 7.2 | CVSSv2: NA | VMScore: 820 | EPSS: 0.00211 | KEV: Not Included
Published: 13/02/2025 Updated: 14/02/2025

Vulnerability Summary

SQL Injection in PHPGurukul Land Record System v1.0 Remote Code Execution

A SQL Injection vulnerability exists in PHPGurukul Land Record System version 1.0 within the /admin/admin-profile.php endpoint. This security weakness allows remote attackers to execute arbitrary code by manipulating the contactnumber parameter through a POST request.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgurukul land record system 1.0