CVE-2025-9814: PHPGurukul Beauty Parlour Management System contact-us.php sql injection
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1.1. Impacted is an unknown function of the file /admin/contact-us.php. The manipulation of the argument mobnumber results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9814?
CVE-2025-9814 is considered a high-severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2025-9814?
To fix CVE-2025-9814, sanitize and validate the 'mobnumber' input in the /admin/contact-us.php file to prevent SQL injection.
What type of attack is possible with CVE-2025-9814?
CVE-2025-9814 allows remote attackers to execute SQL injection attacks through the mobnumber argument.
Which software is affected by CVE-2025-9814?
CVE-2025-9814 affects the PHPGurukul Beauty Parlour Management System version 1.1.
Is CVE-2025-9814 remotely exploitable?
Yes, CVE-2025-9814 is remotely exploitable, allowing attackers to exploit the vulnerability from afar.