CVE-2025-11507: PHPGurukul Beauty Parlour Management System search-invoices.php sql injection
A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /admin/search-invoices.php. This manipulation of the argument searchdata causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11507?
CVE-2025-11507 has a high severity due to the potential for remote SQL injection attacks.
How do I fix CVE-2025-11507?
To fix CVE-2025-11507, ensure that user input is properly sanitized and validate all parameters in the searchdata argument.
What software does CVE-2025-11507 affect?
CVE-2025-11507 affects the PHPGurukul Beauty Parlour Management System version 1.1.
Can CVE-2025-11507 be exploited remotely?
Yes, CVE-2025-11507 can be exploited remotely, allowing attackers to execute SQL injection attacks.
What are the risks associated with CVE-2025-11507?
The risks associated with CVE-2025-11507 include unauthorized data access, data manipulation, and potential system compromise.