First published: Thu May 01 2025(Updated: )
A vulnerability, which was classified as critical, has been found in PHPGurukul Pre-School Enrollment System 1.0. Affected by this issue is some unknown functionality of the file /admin/enrollment-details.php. The manipulation of the argument Status leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
PHPGurukul Pre-School Enrollment System Project |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4154 is classified as a critical vulnerability.
CVE-2025-4154 is an SQL injection vulnerability affecting the PHPGurukul Pre-School Enrollment System.
CVE-2025-4154 allows an attacker to manipulate the 'Status' argument in enrollment-details.php to execute arbitrary SQL commands.
To fix CVE-2025-4154, validate and sanitize user inputs before processing them in SQL queries.
The vulnerability information does not specify affected versions, so it is advisable to assess all instances of the software for potential risks.