CVE-2025-4108: PHPGurukul Student Record System add-subject.php sql injection
A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an unknown function of the file /add-subject.php. The manipulation of the argument sub1 leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4108?
CVE-2025-4108 is classified as a critical vulnerability due to its potential for remote SQL injection.
How do I fix CVE-2025-4108?
To fix CVE-2025-4108, it is recommended to validate and sanitize user inputs and implement prepared statements for database queries.
What software is affected by CVE-2025-4108?
CVE-2025-4108 affects PHPGurukul Student Record System version 3.20.
Can CVE-2025-4108 be exploited remotely?
Yes, CVE-2025-4108 can be exploited remotely through SQL injection in the affected software.
What should I do if I am using PHPGurukul Student Record System 3.20?
If using PHPGurukul Student Record System 3.20, you should apply the recommended security updates and mitigations to protect against CVE-2025-4108.