CVE-2025-4941: PHPGurukul Credit Card Application Management System index.php sql injection
A vulnerability, which was classified as critical, was found in PHPGurukul Credit Card Application Management System 1.0. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4941?
CVE-2025-4941 is classified as a critical vulnerability due to its potential for SQL injection attacks.
How does CVE-2025-4941 affect the PHPGurukul Credit Card Application Management System?
CVE-2025-4941 affects the PHPGurukul Credit Card Application Management System by allowing SQL injection through the manipulation of the Username argument in the /admin/index.php file.
How can I fix CVE-2025-4941?
To fix CVE-2025-4941, sanitize and validate user inputs to prevent SQL injection, and consider applying security patches or updates from the vendor.
What systems are impacted by CVE-2025-4941?
CVE-2025-4941 specifically impacts version 1.0 of the PHPGurukul Credit Card Application Management System.
Is CVE-2025-4941 easy to exploit?
Yes, CVE-2025-4941 is considered easy to exploit due to the nature of the SQL injection vulnerability.