CVE-2025-5658: PHPGurukul Complaint Management System updatecomplaint.php sql injection
Published Jun 5, 2025
·Updated
A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 2.0. Affected is an unknown function of the file /admin/updatecomplaint.php. The manipulation of the argument Status leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
Phpgurukul Complaint Management system
Phpgurukul Complaint Management system=2.0
Event History
Jun 5, 2025
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-5658?
CVE-2025-5658 is classified as a critical vulnerability.
2
What type of vulnerability is CVE-2025-5658?
CVE-2025-5658 is a SQL injection vulnerability.
3
How do I fix CVE-2025-5658?
To fix CVE-2025-5658, sanitize and validate all user inputs in the affected file /admin/updatecomplaint.php.
4
Who is affected by CVE-2025-5658?
The vulnerability affects users of PHPGurukul Complaint Management System version 2.0.
5
Can CVE-2025-5658 be exploited remotely?
Yes, CVE-2025-5658 can be exploited remotely.