CVE-2025-3137: PHPGurukul Online Security Guards Hiring System changeimage.php sql injection
A vulnerability, which was classified as critical, was found in PHPGurukul Online Security Guards Hiring System 1.0. Affected is an unknown function of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3137?
CVE-2025-3137 is classified as a critical vulnerability due to its potential for SQL injection exploitation.
How do I fix CVE-2025-3137?
To fix CVE-2025-3137, sanitize and validate the input parameters in the /admin/changeimage.php file to prevent SQL injection.
What systems are affected by CVE-2025-3137?
CVE-2025-3137 affects the PHPGurukul Online Security Guards Hiring System version 1.0.
What type of attack can be executed with CVE-2025-3137?
CVE-2025-3137 allows attackers to execute SQL injection attacks through the editid argument.
Is there a patch available for CVE-2025-3137?
No specific patch is available for CVE-2025-3137, but application of input validation techniques can mitigate the risk.