CVE-2025-5250: PHPGurukul News Portal Project edit-category.php sql injection
Published May 27, 2025
·Updated
A vulnerability was found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit-category.php. The manipulation of the argument Category leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Phpgurukul News Portal Project
Phpgurukul News Portal Project=4.1
Event History
May 27, 2025
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Jun 23, 57411
Event
via FIRST·06:11 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-5250?
CVE-2025-5250 is classified as a critical vulnerability.
2
What type of vulnerability is CVE-2025-5250?
CVE-2025-5250 is a SQL injection vulnerability.
3
What is affected by CVE-2025-5250?
CVE-2025-5250 affects the /admin/edit-category.php file in PHPGurukul News Portal Project 4.1.
4
How can an attacker exploit CVE-2025-5250?
An attacker can exploit CVE-2025-5250 remotely by manipulating the Category argument.
5
How do I fix CVE-2025-5250?
To fix CVE-2025-5250, ensure proper input validation and parameterized queries in the affected code.