CVE-2025-5251: PHPGurukul News Portal Project edit-subcategory.php sql injection
Published May 27, 2025
·Updated
A vulnerability was found in PHPGurukul News Portal Project 4.1. It has been classified as critical. This affects an unknown part of the file /admin/edit-subcategory.php. The manipulation of the argument Category leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Phpgurukul News Portal Project
Phpgurukul News Portal Project=4.1
Event History
May 27, 2025
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Jun 23, 57411
Event
via FIRST·06:10 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-5251?
CVE-2025-5251 has been classified as critical.
2
How do I fix CVE-2025-5251?
To fix CVE-2025-5251, sanitize user inputs in the /admin/edit-subcategory.php file to prevent SQL injection.
3
What type of vulnerability is CVE-2025-5251?
CVE-2025-5251 is an SQL injection vulnerability.
4
Can CVE-2025-5251 be exploited remotely?
Yes, CVE-2025-5251 can be exploited remotely.
5
Which software is affected by CVE-2025-5251?
CVE-2025-5251 affects the PHPGurukul News Portal Project version 4.1.