CVE-2025-5370: PHPGurukul News Portal forgot-password.php sql injection
A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. Affected by this vulnerability is an unknown functionality of the file /admin/forgot-password.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5370?
CVE-2025-5370 is classified as a critical vulnerability due to its potential for remote exploitation via SQL injection.
How do I fix CVE-2025-5370?
To fix CVE-2025-5370, it is recommended to sanitize and validate inputs carefully in the /admin/forgot-password.php file to prevent SQL injection.
What type of vulnerability is CVE-2025-5370?
CVE-2025-5370 is an SQL injection vulnerability affecting the PHPGurukul News Portal.
Which software versions are affected by CVE-2025-5370?
CVE-2025-5370 affects PHPGurukul News Portal version 4.1.
Can CVE-2025-5370 be exploited remotely?
Yes, CVE-2025-5370 can be exploited remotely by manipulating the Username parameter in the affected functionality.