6.3
CVSSv3

CVE-2025-5554

CVSSv4: 5.3 | CVSSv3: 6.3 | CVSSv2: 6.5 | VMScore: 630 | EPSS: 0.00028 | KEV: Not Included
Published: 04/06/2025 Updated: 04/06/2025

Vulnerability Summary

SQL Injection in PHPGurukul Rail Pass Management System 1.0 via Date Arguments

A critical vulnerability exists in PHPGurukul Rail Pass Management System version 1.0, specifically within the /admin/pass-bwdates-reports-details.php file. The vulnerability allows an attacker to perform SQL injection by manipulating the fromdate or todate arguments. This security issue can be exploited remotely, posing a significant risk to the application. Since the exploit details have been publicly disclosed, there is a potential for malicious actors to take advantage of this vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgurukul rail pass management system