First published: Sun Apr 20 2025(Updated: )
A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/view-appointment.php?viewid=11. The manipulation of the argument remark leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
phpgurukul Men Salon Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3828 is classified as a critical severity vulnerability due to its potential for SQL injection.
To fix CVE-2025-3828, ensure proper input validation and sanitization in the file /admin/view-appointment.php.
Exploitation of CVE-2025-3828 could allow attackers to execute arbitrary SQL commands on the database.
CVE-2025-3828 affects PHPGurukul Men Salon Management System version 1.0.
You can verify vulnerability by testing the /admin/view-appointment.php endpoint for SQL injection through crafted input.