CVE-2025-45021

A SQL Injection vulnerability was identified in the admin/edit-directory.php file of the PHPGurukul Directory Management System v2.0. Attackers can exploit this vulnerability via the email parameter in a POST request to execute arbitrary SQL commands.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpgurukul:directory_management_system:2.0:*:*:*:*:*:*:*

History

09 May 2025, 13:43

Type Values Removed Values Added
CPE cpe:2.3:a:phpgurukul:directory_management_system:2.0:*:*:*:*:*:*:*
First Time Phpgurukul
Phpgurukul directory Management System
References () https://github.com/rtnthakur/CVE/blob/main/PHPGurukul/Directory%20Management%20System/SQL/SQl_Injection_in_edit-directory.md - () https://github.com/rtnthakur/CVE/blob/main/PHPGurukul/Directory%20Management%20System/SQL/SQl_Injection_in_edit-directory.md - Exploit, Third Party Advisory

02 May 2025, 13:53

Type Values Removed Values Added
Summary
  • (es) Se identificó una vulnerabilidad de inyección SQL en el archivo admin/edit-directory.php de PHPGurukul Directory Management System v2.0. Los atacantes pueden explotar esta vulnerabilidad mediante el parámetro de correo electrónico en una solicitud POST para ejecutar comandos SQL arbitrarios.

30 Apr 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CWE CWE-89

30 Apr 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-30 14:15

Updated : 2025-05-09 13:43


NVD link : CVE-2025-45021

Mitre link : CVE-2025-45021

CVE.ORG link : CVE-2025-45021


JSON object : View

Products Affected

phpgurukul

  • directory_management_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')