CVE-2025-25387: SQL Injection
A SQL Injection vulnerability was found in /admin/manage-propertytype.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the propertytype POST request parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25387?
CVE-2025-25387 is a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-25387?
To fix CVE-2025-25387, you should sanitize and validate the propertytype POST request parameter in the /admin/manage-propertytype.php script.
What impact does CVE-2025-25387 have on PHPGurukul Land Record System?
CVE-2025-25387 allows remote attackers to execute arbitrary SQL commands, which could compromise the integrity and confidentiality of the database.
Is CVE-2025-25387 exploitable in the default configuration?
Yes, CVE-2025-25387 is exploitable in the default configuration of PHPGurukul Land Record System v1.0 without additional security measures.
What version of PHPGurukul Land Record System is affected by CVE-2025-25387?
CVE-2025-25387 affects PHPGurukul Land Record System version 1.0.