CVE-2025-5659: PHPGurukul Complaint Management System profile.php sql injection
A vulnerability classified as critical was found in PHPGurukul Complaint Management System 2.0. Affected by this vulnerability is an unknown functionality of the file /user/profile.php. The manipulation of the argument pincode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5659?
CVE-2025-5659 is classified as a critical vulnerability.
What type of vulnerability is CVE-2025-5659?
CVE-2025-5659 is an SQL injection vulnerability found in the PHPGurukul Complaint Management System.
How can I exploit CVE-2025-5659?
CVE-2025-5659 can be exploited by manipulating the 'pincode' parameter in the /user/profile.php file.
How do I fix CVE-2025-5659?
Fixing CVE-2025-5659 involves sanitizing user input to prevent SQL injection in the affected PHP file.
What are the potential consequences of CVE-2025-5659?
Exploitation of CVE-2025-5659 can lead to unauthorized database access and potential data breaches.