CVE-2025-57147: SQL Injection
Published Sep 3, 2025
·Updated
A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2.0. The vulnerability is due to lack of input validation of multiple parameters including fullname, email, and contactno in user/registration.php.
Affected Software
2 affected components
Phpgurukul Complaint Management system
Phpgurukul Complaint Management system=2.0
Event History
Sep 3, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-57147?
CVE-2025-57147 is classified as a critical SQL Injection vulnerability.
2
How do I fix CVE-2025-57147?
To fix CVE-2025-57147, implement proper input validation and sanitization for the affected parameters in user/registration.php.
3
What software is affected by CVE-2025-57147?
CVE-2025-57147 affects Phpgurukul Complaint Management System version 2.0.
4
What parameters are vulnerable in CVE-2025-57147?
The parameters vulnerable in CVE-2025-57147 include fullname, email, and contactno.
5
Can CVE-2025-57147 lead to data leakage?
Yes, exploitation of CVE-2025-57147 can allow attackers to access and manipulate the database, potentially leading to data leakage.