CVE-2025-4880: PHPGurukul News Portal aboutus.php sql injection
Published May 18, 2025
·Updated
A vulnerability has been found in PHPGurukul News Portal 4.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/aboutus.php. The manipulation of the argument pagetitle leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Phpgurukul News Portal
Phpgurukul News Portal=4.1
Event History
May 18, 2025
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-4880?
CVE-2025-4880 is classified as a critical vulnerability.
2
How does CVE-2025-4880 affect PHPGurukul News Portal?
CVE-2025-4880 affects the functionality of the file /admin/aboutus.php, allowing for SQL injection.
3
Can CVE-2025-4880 be exploited remotely?
Yes, CVE-2025-4880 can be exploited remotely.
4
What is the cause of the SQL injection in CVE-2025-4880?
The SQL injection vulnerability in CVE-2025-4880 is caused by improper handling of the argument pagetitle.
5
How do I fix CVE-2025-4880?
To fix CVE-2025-4880, it is recommended to sanitize and validate user inputs in the affected file.