Vulnerability Details
Basic Information
| Title | CVE-2025-3828 PHPGurukul Men Salon Management System view-appointment.php sql injection |
|---|---|
| Type | cvelist |
| Published | 2025-04-20T15:31:05 |
| Last Seen | 2025-04-20T16:17:11 |
| CVSS Score | 7.3 (HIGH) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | LOW |
| Integrity Impact | LOW |
| Availability Impact | LOW |
CVE Information
| CVE IDs | CVE-2025-3828 |
|---|---|
| CWE | CWE-74, CWE-89 |
| Bulletin Family | cve |
Description
A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/view-appointment.php?viewid=11. The manipulation of the argument remark leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Impact Assessment
| Base Score | 7.3 |
|---|---|
| Severity | HIGH |