CVE 6.9 MEDIUM

PHPGurukul Small CRM create-ticket.php sql injection_CVE-2025-10664

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was determined in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /create-ticket.php. Executing manipulation of the argument subject can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

Basic Information

ID CVE-2025-10664
Source VulDB
Published Sep 18, 2025 at 12:02

Affected Product

Vendor PHPGurukul
Product Small CRM
Version 4.0
Affected Versions PHPGurukul Small CRM 4.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.