CVE-2025-3312: PHPGurukul Men Salon Management System add-customer-services.php sql injection
A vulnerability, which was classified as critical, has been found in PHPGurukul Men Salon Management System 1.0. This issue affects some unknown processing of the file /admin/add-customer-services.php. The manipulation of the argument sids[] leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3312?
CVE-2025-3312 is classified as a critical vulnerability.
How do I fix CVE-2025-3312?
To fix CVE-2025-3312, validate and sanitize the input for the 'sids[]' parameter in the /admin/add-customer-services.php file to prevent SQL injection.
What type of vulnerability is CVE-2025-3312?
CVE-2025-3312 is an SQL injection vulnerability.
Which software is affected by CVE-2025-3312?
CVE-2025-3312 affects PHPGurukul Men Salon Management System version 1.0.
What could be the potential impact of exploiting CVE-2025-3312?
Exploiting CVE-2025-3312 may allow an attacker to execute arbitrary SQL queries on the database.