CVE-2025-3972: PHPGurukul COVID19 Testing Management System bwdates-report-result.php sql injection
A vulnerability, which was classified as critical, has been found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /bwdates-report-result.php. The manipulation of the argument todate leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3972?
CVE-2025-3972 is classified as a critical vulnerability.
How do I fix CVE-2025-3972?
To fix CVE-2025-3972, it is recommended to update the PHPGurukul COVID19 Testing Management System to a patched version.
What type of vulnerability is CVE-2025-3972?
CVE-2025-3972 is an SQL injection vulnerability.
Which file is affected by CVE-2025-3972?
The affected file in CVE-2025-3972 is /bwdates-report-result.php.
What does the manipulation of 'todate' lead to in CVE-2025-3972?
The manipulation of the 'todate' argument in CVE-2025-3972 leads to SQL injection.