CVE-2025-4028: PHPGurukul COVID19 Testing Management System profile.php sql injection
A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4028?
CVE-2025-4028 is classified as critical due to the potential for SQL injection vulnerabilities.
How do I fix CVE-2025-4028?
To fix CVE-2025-4028, sanitize and validate all user inputs, especially the mobilenumber parameter in the /profile.php file.
Which software is affected by CVE-2025-4028?
CVE-2025-4028 affects PHPGurukul COVID19 Testing Management System version 1.0.
What type of attack can be executed through CVE-2025-4028?
CVE-2025-4028 allows for SQL injection attacks, which can compromise database integrity.
What is the impact of CVE-2025-4028 on user data?
The impact of CVE-2025-4028 can lead to unauthorized access and potential data leaks from the database.