CVE Details
Basic Information
| Title | PHPGurukul Notice Board System admin-profile.php sql injection |
|---|---|
| Type | cve |
| Published | 2025-06-05T05:00:19.690Z |
| Last Seen |
Product Information
| Vendor | PHPGurukul |
|---|---|
| Product | Notice Board System |
| Version | 1.0 |
CVSS Information
| Base Score | 5.3 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | The PHPGurukul Notice Board System 1.0 is vulnerable to SQL injection via the ‘mobilenumber’ parameter in the /admin-profile.php file. This allows attackers to execute arbitrary SQL commands, potentially compromising the database. The vulnerability is remotely exploitable and has been publicly disclosed. |
|---|---|
| AI Severity | Critical |
| Vendor | PHPGurukul |
| Product | Notice Board System |
| Affected Version | 1.0 |
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-89, CWE-74 |
| Bulletin Family | |
| Source Data | PHPGurukul Notice Board System 1.0 |
Source Information
| Source Data | PHPGurukul Notice Board System 1.0 |
|---|---|
| Source Link |
Description
A vulnerability has been found in PHPGurukul Notice Board System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin-profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
CVSS Score Summary
Base Score: 5.3 (MEDIUM)