CVE-2025-2642: PHPGurukul Art Gallery Management System edit-art-product-detail.php sql injection
A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.0. This affects an unknown part of the file /admin/edit-art-product-detail.php?editid=2. The manipulation of the argument editide/sprice/description leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2642?
CVE-2025-2642 is classified as a critical vulnerability that allows for SQL injection.
How do I fix CVE-2025-2642?
To fix CVE-2025-2642, ensure proper sanitization and validation of user inputs in the affected parameter of the PHPGurukul Art Gallery Management System.
Which software is affected by CVE-2025-2642?
CVE-2025-2642 affects the PHPGurukul Art Gallery Management System version 1.0.
What kind of attack is possible with CVE-2025-2642?
CVE-2025-2642 enables SQL injection attacks through specific parameters, potentially allowing unauthorized database access.
What component of the software is vulnerable in CVE-2025-2642?
The vulnerability in CVE-2025-2642 resides in the /admin/edit-art-product-detail.php file, affecting the editid, sprice, and description parameters.