CVE-2025-3973: PHPGurukul COVID19 Testing Management System check_availability.php sql injection
A vulnerability, which was classified as critical, was found in PHPGurukul COVID19 Testing Management System 1.0. This affects an unknown part of the file /checkavailability.php. The manipulation of the argument mobnumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3973?
CVE-2025-3973 is classified as a critical vulnerability.
How does CVE-2025-3973 affect the PHPGurukul COVID19 Testing Management System?
CVE-2025-3973 affects the /check_availability.php file and allows for SQL injection through manipulation of the mobnumber argument.
What can an attacker achieve by exploiting CVE-2025-3973?
An attacker can potentially execute arbitrary SQL commands on the backend database by exploiting CVE-2025-3973.
How do I fix CVE-2025-3973?
To fix CVE-2025-3973, it is recommended to sanitize and validate user inputs to prevent SQL injection.
Which versions of the PHPGurukul COVID19 Testing Management System are affected by CVE-2025-3973?
CVE-2025-3973 affects version 1.0 of the PHPGurukul COVID19 Testing Management System.