CVE-2025-5554: PHPGurukul Rail Pass Management System pass-bwdates-reports-details.php sql injection
A vulnerability, which was classified as critical, has been found in PHPGurukul Rail Pass Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/pass-bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5554?
CVE-2025-5554 is classified as a critical vulnerability.
How do I fix CVE-2025-5554?
To fix CVE-2025-5554, ensure that your PHPGurukul Rail Pass Management System is updated to the latest version.
What types of attacks can CVE-2025-5554 allow?
CVE-2025-5554 can allow attackers to perform SQL injection attacks via the fromdate and todate parameters.
Which software is affected by CVE-2025-5554?
CVE-2025-5554 affects the PHPGurukul Rail Pass Management System version 1.0.
Where is the vulnerable file related to CVE-2025-5554 located?
The vulnerable file for CVE-2025-5554 is located at /admin/pass-bwdates-reports-details.php.