CVE-2025-6914: PHPGurukul Student Record System edit-student.php sql injection
A vulnerability classified as critical was found in PHPGurukul Student Record System 3.2. Affected by this vulnerability is an unknown functionality of the file /edit-student.php. The manipulation of the argument fmarks2 leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6914?
CVE-2025-6914 is classified as a critical vulnerability due to its potential to allow remote SQL injection.
How do I fix CVE-2025-6914?
To fix CVE-2025-6914, validate and sanitize inputs in the /edit-student.php file to protect against SQL injection.
What systems are affected by CVE-2025-6914?
CVE-2025-6914 affects PHPGurukul Student Record System version 3.2.
What is the primary attack vector for CVE-2025-6914?
The primary attack vector for CVE-2025-6914 is remote exploitation through crafted input to the fmarks2 argument.
Can CVE-2025-6914 be exploited without authentication?
Yes, CVE-2025-6914 can be exploited remotely, meaning authentication is not required for an attacker to exploit the vulnerability.