CVE-2025-4156: PHPGurukul Boat Booking System change-image.php sql injection
A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/change-image.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4156?
CVE-2025-4156 is classified as a critical vulnerability.
How does CVE-2025-4156 allow for exploitation?
CVE-2025-4156 allows for exploitation through SQL injection via manipulated arguments in the /admin/change-image.php file.
What systems are affected by CVE-2025-4156?
CVE-2025-4156 affects the PHPGurukul Boat Booking System 1.0.
Can CVE-2025-4156 be exploited remotely?
Yes, CVE-2025-4156 can be exploited remotely.
How can I protect my system from CVE-2025-4156?
To protect your system from CVE-2025-4156, it is recommended to patch or upgrade the PHPGurukul Boat Booking System to the latest version.