CVE-2025-25357: SQL Injection
Published Feb 13, 2025
·Updated
A SQL Injection vulnerability was found in /admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the email POST request parameter.
Affected Software
2 affected components
Phpgurukul Land Record System
Phpgurukul Land Record System=1.0
Event History
Feb 13, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25357?
CVE-2025-25357 is considered to be a high severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2025-25357?
To fix CVE-2025-25357, you should validate and sanitize all user inputs, particularly the email POST request parameter in /admin/contactus.php.
3
What type of vulnerability is CVE-2025-25357?
CVE-2025-25357 is a SQL Injection vulnerability that can be exploited to execute arbitrary code.
4
Which version of PHPGurukul Land Record System is affected by CVE-2025-25357?
CVE-2025-25357 affects PHPGurukul Land Record System v1.0.
5
Can CVE-2025-25357 be exploited remotely?
Yes, CVE-2025-25357 can be exploited remotely by attackers through the email POST request parameter.