CVE-2025-5226: PHPGurukul Small CRM change-password.php sql injection
A vulnerability has been found in PHPGurukul Small CRM 3.0 and classified as critical. This vulnerability affects unknown code of the file /admin/change-password.php. The manipulation of the argument oldpass leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5226?
CVE-2025-5226 is classified as a critical vulnerability.
How does CVE-2025-5226 affect PHPGurukul Small CRM?
CVE-2025-5226 enables SQL injection through the /admin/change-password.php file.
Can CVE-2025-5226 be exploited remotely?
Yes, CVE-2025-5226 can be exploited remotely.
What input leads to the vulnerability in CVE-2025-5226?
The manipulation of the argument 'oldpass' leads to the SQL injection in CVE-2025-5226.
How can I mitigate CVE-2025-5226 in my application?
To mitigate CVE-2025-5226, you should update PHPGurukul Small CRM to the latest version that addresses this vulnerability.