CVE Details
Basic Information
| Title | PHPGurukul Vehicle Parking Management System bwdates-reports-details.php sql injection |
|---|---|
| Type | cve |
| Published | 2025-07-13T06:32:06.158Z |
| Modified | 2025-07-13T06:32:06.158Z |
Product Information
| Vendor | PHPGurukul |
|---|---|
| Product | Vehicle Parking Management System |
| Version | 1.13 |
CVSS Information
| Base Score | 5.3 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P |
AI Analysis
| AI Description | A critical SQL injection vulnerability exists in PHPGurukul’s Vehicle Parking Management System version 1.13. This vulnerability allows remote attackers to inject malicious SQL code, potentially leading to unauthorized data access and system compromise. |
|---|---|
| AI Severity | High |
| AI Vendor | PHPGurukul |
| AI Product | Vehicle Parking Management System |
| AI Version | 1.13 |
Affected Products
- PHPGurukul Vehicle Parking Management System 1.13
Additional Information
| CWE List | CWE-89, CWE-74 |
|---|---|
| Source | VulDB |
Description
A vulnerability has been found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.