First published: Wed Apr 30 2025(Updated: )
A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an unknown function of the file /add-subject.php. The manipulation of the argument sub1 leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Student Record System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4108 is classified as a critical vulnerability due to its potential for remote SQL injection.
To fix CVE-2025-4108, it is recommended to validate and sanitize user inputs and implement prepared statements for database queries.
CVE-2025-4108 affects PHPGurukul Student Record System version 3.20.
Yes, CVE-2025-4108 can be exploited remotely through SQL injection in the affected software.
If using PHPGurukul Student Record System 3.20, you should apply the recommended security updates and mitigations to protect against CVE-2025-4108.