CVE-2025-7165: PHPGurukul/Campcodes Cyber Cafe Management System forgot-password.php sql injection
A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7165?
CVE-2025-7165 is classified as a critical severity vulnerability.
How does CVE-2025-7165 impact the security of the application?
CVE-2025-7165 allows for SQL injection through the 'email' parameter in the /forgot-password.php file.
How do I fix CVE-2025-7165?
To fix CVE-2025-7165, ensure proper sanitization and validation of the input parameters in the affected PHP script.
Which software versions are affected by CVE-2025-7165?
CVE-2025-7165 affects version 1.0 of the PHPGurukul Campcodes Cyber Cafe Management System.
What should I do if I am using PHPGurukul/Campcodes Cyber Cafe Management System?
If you are using the affected version, it's essential to update your system or patch it to mitigate the vulnerability described in CVE-2025-7165.