First published: Tue May 06 2025(Updated: )
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /edit-phlebotomist.php. The manipulation of the argument mobilenumber leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
PHPGurukul Nipah Virus Testing Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4306 has been classified as a critical vulnerability.
CVE-2025-4306 is an SQL injection vulnerability.
To fix CVE-2025-4306, sanitize and validate user input for the 'mobilenumber' parameter in the /edit-phlebotomist.php file.
CVE-2025-4306 affects PHPGurukul Nipah Virus Testing Management System version 1.0.
Exploiting CVE-2025-4306 can allow an attacker to execute arbitrary SQL queries on the database.