CVE-2025-11415: PHPGurukul Beauty Parlour Management System customer-list.php sql injection
A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file /admin/customer-list.php. Such manipulation of the argument delid leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11415?
CVE-2025-11415 has a high severity due to its potential for remote SQL injection attacks.
How do I fix CVE-2025-11415?
To fix CVE-2025-11415, validate and sanitize all user inputs in the /admin/customer-list.php file to prevent SQL injection.
Which software versions are affected by CVE-2025-11415?
CVE-2025-11415 affects PHPGurukul Beauty Parlour Management System version 1.1.
Can CVE-2025-11415 be exploited remotely?
Yes, CVE-2025-11415 can be exploited remotely through manipulation of the delid parameter.
What type of vulnerability is CVE-2025-11415?
CVE-2025-11415 is identified as an SQL injection vulnerability.