Vulnerability Details
Basic Information
| Title | CVE-2025-4214 PHPGuruku Online DJ Booking Management System booking-bwdates-reports-details.php sql injection |
|---|---|
| Type | vulnrichment |
| Published | 2025-05-02T19:31:04 |
| Last Seen | 2025-05-02T20:32:30 |
| CVSS Score | 7.3 (HIGH) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | LOW |
| Integrity Impact | LOW |
| Availability Impact | LOW |
CVE Information
| CVE IDs | CVE-2025-4214 |
|---|---|
| CWE | CWE-89, CWE-74 |
| Bulletin Family | cve |
Description
A vulnerability was found in PHPGuruku Online DJ Booking Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/booking-bwdates-reports-details.php. The manipulation of the argument fromdate leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Impact Assessment
| Base Score | 7.3 |
|---|---|
| Severity | HIGH |