CVE-2025-7481: PHPGurukul Vehicle Parking Management System profile.php sql injection
A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been classified as critical. This affects an unknown part of the file /users/profile.php. The manipulation of the argument firstname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7481?
CVE-2025-7481 is classified as a critical vulnerability.
How does CVE-2025-7481 exploit occur?
CVE-2025-7481 allows SQL injection through manipulation of the 'firstname' argument in /users/profile.php.
What software is affected by CVE-2025-7481?
CVE-2025-7481 affects PHPGurukul Vehicle Parking Management System version 1.13.
How do I mitigate CVE-2025-7481?
To mitigate CVE-2025-7481, validate and sanitize user inputs to prevent SQL injection.
What are the potential impacts of CVE-2025-7481?
CVE-2025-7481 can allow attackers to execute arbitrary SQL queries, potentially leading to data breaches.