First published: Mon Mar 24 2025(Updated: )
A vulnerability classified as critical has been found in PHPGurukul eLearning System 1.0. Affected is an unknown function of the file /user/index.php of the component Image Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
PHPGurukul eLearning System | ||
PHPGurukul eLearning System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2687 is classified as a critical vulnerability.
CVE-2025-2687 affects the Image Handler component of the PHPGurukul eLearning System, allowing for unrestricted file uploads.
Exploiting CVE-2025-2687 may lead to the remote execution of arbitrary code due to unauthorized file uploads.
To mitigate CVE-2025-2687, ensure that file upload functionality has strict file type and size restrictions.
As of now, the developers have not released a patch for CVE-2025-2687, so users should implement workarounds to secure their systems.