CVE-2025-4073: PHPGurukul Student Record System change-password.php sql injection
A vulnerability was found in PHPGurukul Student Record System 3.20. It has been classified as critical. Affected is an unknown function of the file /change-password.php. The manipulation of the argument currentpassword leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4073?
CVE-2025-4073 has been classified as a critical vulnerability.
What kind of vulnerability is CVE-2025-4073?
CVE-2025-4073 is an SQL injection vulnerability affecting the currentpassword parameter.
Which software is affected by CVE-2025-4073?
CVE-2025-4073 affects the PHPGurukul Student Record System 3.20.
How do I fix CVE-2025-4073?
To fix CVE-2025-4073, ensure proper validation and sanitization of input parameters used in SQL queries.
What can be the impact of exploiting CVE-2025-4073?
Exploiting CVE-2025-4073 can allow an attacker to execute arbitrary SQL commands on the database.