CVE-2025-9024: PHPGurukul Beauty Parlour Management System book-appointment.php sql injection
A vulnerability was found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /book-appointment.php. The manipulation of the argument Message leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9024?
CVE-2025-9024 has a high severity due to its potential for SQL injection attacks.
How do I fix CVE-2025-9024?
To fix CVE-2025-9024, sanitize user inputs in the /book-appointment.php file to prevent SQL injection.
What type of vulnerability is CVE-2025-9024?
CVE-2025-9024 is an SQL injection vulnerability affecting the PHPGurukul Beauty Parlour Management System.
Can CVE-2025-9024 be exploited remotely?
Yes, CVE-2025-9024 can be exploited remotely, allowing attackers to manipulate the application without direct access.
Which software is affected by CVE-2025-9024?
CVE-2025-9024 affects version 1.1 of the PHPGurukul Beauty Parlour Management System.