First published: Mon Mar 24 2025(Updated: )
A vulnerability, which was classified as critical, was found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file /add-subadmin.php. The manipulation of the argument sadminusername leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bank Locker Management System | ||
Bank Locker Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2676 is classified as a critical vulnerability due to its potential for SQL injection attacks.
Fixing CVE-2025-2676 requires sanitizing and validating all user input in the /add-subadmin.php file to prevent SQL injection.
CVE-2025-2676 specifically affects the /add-subadmin.php file in the PHPGurukul Bank Locker Management System.
Yes, CVE-2025-2676 can lead to data breaches if an attacker successfully exploits the SQL injection vulnerability.
Any users of the PHPGurukul Bank Locker Management System version 1.0 are potentially impacted by CVE-2025-2676.