CVE-2025-3796: PHPGurukul Men Salon Management System contact-us.php sql injection
A vulnerability classified as critical has been found in PHPGurukul Men Salon Management System 1.0. This affects an unknown part of the file /admin/contact-us.php. The manipulation of the argument pagetitle/pagedes/email/mobnumber/timing leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3796?
CVE-2025-3796 is classified as critical due to its potential for SQL injection vulnerabilities.
How do I fix CVE-2025-3796?
To resolve CVE-2025-3796, it is recommended to sanitize and validate all user inputs in the affected file /admin/contact-us.php.
What components are affected by CVE-2025-3796?
CVE-2025-3796 affects the PHPGurukul Men Salon Management System version 1.0.
What type of vulnerability is CVE-2025-3796?
CVE-2025-3796 is an SQL injection vulnerability that allows malicious manipulation of database queries.
Is CVE-2025-3796 exploitable remotely?
Yes, CVE-2025-3796 can be exploited remotely by sending specially crafted requests to the vulnerable application.