CVE Details
Basic Information
| Title | CVE-2025-4908 PHPGurukul Daily Expense Tracker System expense-datewise-reports-detailed.php sql injection |
|---|---|
| Type | cve |
| Published | 2025-05-19T03:00:09 |
| Last Seen | 2025-05-19T03:22:09 |
CVSS Information
| Base Score | 0.0 () |
|---|---|
| Attack Vector | |
| Attack Complexity | |
| Privileges Required | |
| User Interaction | |
| Scope | |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A critical SQL injection vulnerability exists in PHPGurukul Daily Expense Tracker System 1.1, specifically in the /expense-datewise-reports-detailed.php file. The vulnerability allows remote attackers to execute arbitrary SQL commands via manipulation of an unspecified argument, potentially leading to unauthorized access or data manipulation. |
|---|---|
| AI Severity | High |
| Vendor | PHPGurukul |
| Product | Daily Expense Tracker System |
| Affected Version | 1.1 |
Additional Information
| CVE List | CVE-2025-4908 |
|---|---|
| CWE List | CWE-89, CWE-74 |
| Bulletin Family | cve |
Description
A vulnerability classified as critical has been found in PHPGurukul Daily Expense Tracker System 1.1. This affects an unknown part of the file /expense-datewise-reports-detailed.php. The manipulation of the argument…
CVSS Score Summary
Base Score: %!f(string=#) ()