CVE-2025-11506: PHPGurukul Beauty Parlour Management System search-appointment.php sql injection
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unknown function of the file /admin/search-appointment.php. The manipulation of the argument searchdata results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11506?
CVE-2025-11506 has been classified as a high severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2025-11506?
To mitigate CVE-2025-11506, you should sanitize and validate user input in the /admin/search-appointment.php file to prevent SQL injection.
Which software is affected by CVE-2025-11506?
CVE-2025-11506 affects PHPGurukul Beauty Parlour Management System version 1.1.
Can CVE-2025-11506 lead to data compromise?
Yes, CVE-2025-11506 can lead to unauthorized access and data compromise through SQL injection.
What actions should be taken immediately regarding CVE-2025-11506?
Immediately applying input validation and updating the system will help mitigate the risks associated with CVE-2025-11506.