CVE-2025-5782: PHPGurukul Employee Record Management System resetpassword.php sql injection
A vulnerability, which was classified as critical, has been found in PHPGurukul Employee Record Management System 1.3. Affected by this issue is some unknown functionality of the file /resetpassword.php. The manipulation of the argument newpassword leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5782?
CVE-2025-5782 is classified as a critical vulnerability.
What type of vulnerability is CVE-2025-5782?
CVE-2025-5782 is an SQL injection vulnerability.
How does CVE-2025-5782 affect the PHPGurukul Employee Record Management System?
CVE-2025-5782 affects the resetpassword.php file, allowing attackers to manipulate the newpassword argument.
How do I fix CVE-2025-5782?
To fix CVE-2025-5782, sanitize and validate all user inputs and use prepared statements to interact with the database.
Which version of the PHPGurukul Employee Record Management System is affected by CVE-2025-5782?
CVE-2025-5782 affects version 1.3 of the PHPGurukul Employee Record Management System.