First published: Sat Mar 22 2025(Updated: )
A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.1. Affected is an unknown function of the file /art-enquiry.php. The manipulation of the argument eid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
PHPGurukul Art Gallery Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2628 is classified as a critical vulnerability.
To fix CVE-2025-2628, ensure that you sanitize and validate all inputs in the /art-enquiry.php file to prevent SQL injection.
CVE-2025-2628 allows for remote SQL injection attacks that can compromise the database of the Art Gallery Management System.
CVE-2025-2628 affects version 1.1 of the PHPGurukul Art Gallery Management System.
You can test for CVE-2025-2628 by attempting to input malicious SQL commands through the eid parameter in the /art-enquiry.php file.