CVE-2025-5212: PHPGurukul Employee Record Management System editempexp.php sql injection
A vulnerability was found in PHPGurukul Employee Record Management System 1.3. It has been classified as critical. Affected is an unknown function of the file /admin/editempexp.php. The manipulation of the argument emp1name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5212?
CVE-2025-5212 has been classified as critical.
How does CVE-2025-5212 affect the PHPGurukul Employee Record Management System?
CVE-2025-5212 allows SQL injection through the manipulation of the argument emp1name in the /admin/editempexp.php file.
What versions of PHPGurukul Employee Record Management System are affected by CVE-2025-5212?
CVE-2025-5212 impacts PHPGurukul Employee Record Management System version 1.3.
How can I remediate CVE-2025-5212?
To fix CVE-2025-5212, ensure that input validation is implemented to prevent SQL injection in the affected function.
What kind of attack can be launched due to CVE-2025-5212?
CVE-2025-5212 allows attackers to exploit SQL injection vulnerabilities, potentially gaining unauthorized access to the database.