CVE-2025-3147: PHPGurukul Boat Booking System add-subadmin.php sql injection
Published Apr 3, 2025
·Updated
A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-subadmin.php. The manipulation of the argument sadminusername leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Phpgurukul Boat Booking System
Phpgurukul Boat Booking System=1.0
Event History
Apr 3, 2025
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-3147?
CVE-2025-3147 is classified as a critical severity vulnerability.
2
How do I fix CVE-2025-3147?
To fix CVE-2025-3147, ensure proper input validation and use prepared statements in SQL queries.
3
What type of vulnerability is CVE-2025-3147?
CVE-2025-3147 is an SQL injection vulnerability.
4
What file is affected by CVE-2025-3147?
CVE-2025-3147 affects the /add-subadmin.php file in the PHPGurukul Boat Booking System.
5
Can CVE-2025-3147 be exploited remotely?
Yes, CVE-2025-3147 can be exploited remotely.