CVE-2025-2640: PHPGurukul Doctor Appointment Management System appointment-bwdates-reports-details.php sql injection
A vulnerability was found in PHPGurukul Doctor Appointment Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /doctor/appointment-bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2640?
CVE-2025-2640 is classified as a critical vulnerability.
Which systems are affected by CVE-2025-2640?
CVE-2025-2640 affects PHPGurukul Doctor Appointment Management System version 1.0.
What type of vulnerability is CVE-2025-2640?
CVE-2025-2640 is a SQL injection vulnerability.
How can I mitigate CVE-2025-2640?
To mitigate CVE-2025-2640, you should sanitize user inputs, specifically the fromdate and todate parameters in URLs.
What potential impact does CVE-2025-2640 have?
CVE-2025-2640 can allow an attacker to manipulate SQL queries, potentially leading to unauthorized data access.