First published: Sat May 03 2025(Updated: )
A vulnerability classified as critical was found in PHPGurukul Online Birth Certificate System 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/between-dates-report.php. The manipulation of the argument fromdate leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Online Birth Certificate System | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4242 is classified as a critical vulnerability due to its potential for SQL injection.
To fix CVE-2025-4242, update to a patched version of PHPGurukul Online Birth Certificate System or implement input validation and prepared statements to mitigate SQL injection risks.
CVE-2025-4242 can facilitate SQL injection attacks, allowing attackers to manipulate the database and access sensitive information.
CVE-2025-4242 affects PHPGurukul Online Birth Certificate System version 2.0.
The vulnerability identified in CVE-2025-4242 is found in the file /admin/between-dates-report.php.