CVE-2025-4304: PHPGurukul Cyber Cafe Management System adminprofile.php sql injection
A vulnerability, which was classified as critical, was found in PHPGurukul Cyber Cafe Management System 1.0. This affects an unknown part of the file /adminprofile.php. The manipulation of the argument mobilenumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4304?
CVE-2025-4304 is classified as a critical vulnerability.
How do I fix CVE-2025-4304?
To fix CVE-2025-4304, you need to sanitize the 'mobilenumber' input to prevent SQL injection.
What systems are affected by CVE-2025-4304?
CVE-2025-4304 affects PHPGurukul Cyber Cafe Management System version 1.0.
What type of vulnerability is CVE-2025-4304?
CVE-2025-4304 is an SQL injection vulnerability that can be exploited remotely.
What file is involved in the CVE-2025-4304 vulnerability?
The vulnerability is found in the /adminprofile.php file of the PHPGurukul Cyber Cafe Management System.