CVE-2025-3370: PHPGurukul Men Salon Management System admin-profile.php sql injection
A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/admin-profile.php. The manipulation of the argument contactnumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3370?
CVE-2025-3370 is classified as a critical vulnerability.
What type of vulnerability is CVE-2025-3370?
CVE-2025-3370 is a SQL injection vulnerability affecting PHPGurukul Men Salon Management System.
How do I fix CVE-2025-3370?
To fix CVE-2025-3370, you should sanitize the input for the contactnumber parameter in the /admin/admin-profile.php file.
What are the potential impacts of CVE-2025-3370?
CVE-2025-3370 could allow an attacker to execute arbitrary SQL queries, potentially compromising the database.
Which software versions are affected by CVE-2025-3370?
CVE-2025-3370 affects PHPGurukul Men Salon Management System version 1.0.