CVE-2025-4812: PHPGurukul Human Metapneumovirus Testing Management System profile.php sql injection
Published May 16, 2025
·Updated
A vulnerability, which was classified as critical, has been found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. This issue affects some unknown processing of the file /profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Phpgurukul Human Metapneumovirus Testing Management System
Phpgurukul Human Metapneumovirus=1.0
Event History
May 16, 2025
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
How can attackers exploit CVE-2025-4812?
Attackers can exploit CVE-2025-4812 by manipulating the mobilenumber argument in the /profile.php file to execute arbitrary SQL commands.