CVE-2025-57149: SQL Injection
Published Sep 3, 2025
·Updated
phpgurukul Complaint Management System 2.0 is vulnerable to SQL Injection in /complaint-details.php via the cid parameter.
Affected Software
2 affected components
Phpgurukul Complaint Management system
Phpgurukul Complaint Management system=2.0
Event History
Sep 3, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-57149?
CVE-2025-57149 has a high severity level due to its potential for SQL Injection exploitation.
2
How do I fix CVE-2025-57149?
To fix CVE-2025-57149, sanitize user inputs and utilize prepared statements for database queries.
3
What systems are affected by CVE-2025-57149?
CVE-2025-57149 affects phpgurukul Complaint Management System version 2.0.
4
What is the attack vector for CVE-2025-57149?
The attack vector for CVE-2025-57149 is the cid parameter in the /complaint-details.php file.
5
Can CVE-2025-57149 be exploited remotely?
Yes, CVE-2025-57149 can be exploited remotely, allowing attackers to execute arbitrary SQL queries.