CVE-2025-4873: PHPGurukul News Portal Login index.php sql injection
A vulnerability has been found in PHPGurukul News Portal 4.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/index.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4873?
CVE-2025-4873 is classified as a critical vulnerability.
What component is affected by CVE-2025-4873?
CVE-2025-4873 affects the Login functionality of the /admin/index.php file in PHPGurukul News Portal 4.1.
How can CVE-2025-4873 be exploited?
CVE-2025-4873 can be exploited through SQL injection by manipulating the Username argument.
How do I fix CVE-2025-4873?
To fix CVE-2025-4873, ensure that your PHPGurukul News Portal is updated to the latest version, and validate and sanitize user inputs.
Which versions of PHPGurukul News Portal are affected by CVE-2025-4873?
CVE-2025-4873 affects PHPGurukul News Portal version 4.1 and potentially earlier versions.