CVE-2025-4766: PHPGurukul Zoo Management System profile.php sql injection
A vulnerability was found in PHPGurukul Zoo Management System 2.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/profile.php. The manipulation of the argument contactnumber leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4766?
CVE-2025-4766 has been declared as critical.
What type of vulnerability is CVE-2025-4766?
CVE-2025-4766 is an SQL injection vulnerability found in the PHPGurukul Zoo Management System 2.1.
Which file is affected by CVE-2025-4766?
The affected file in CVE-2025-4766 is /admin/profile.php.
How does CVE-2025-4766 affect the Zoo Management System?
CVE-2025-4766 allows attackers to manipulate the contactnumber argument to execute SQL injection attacks.
How do I fix CVE-2025-4766?
To fix CVE-2025-4766, validate and sanitize user input on the affected file to prevent SQL injection.