PHPGurukul Employee Record Management System是PHPGurukul公司的一个员工记录管理系统。 PHPGurukul Employee Record Management System 1.3版本存在注入漏洞,该漏洞源于对文件changepassword.php中参数currentpassword的错误操作导致SQL注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PHPGurukul | Employee Record Management System | 1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-4151 | 7.3 HIGH | PHPGurukul Curfew e-Pass Management System pass-bwdates-reports-details.php sql injection |
| CVE-2025-4152 | 7.3 HIGH | PHPGurukul Online Birth Certificate System bwdates-reports-details.php sql injection |
| CVE-2025-4153 | 7.3 HIGH | PHPGurukul Park Ticketing Management System profile.php sql injection |
| CVE-2025-4174 | 7.3 HIGH | PHPGurukul COVID19 Testing Management System login.php sql injection |
| CVE-2025-4176 | 7.3 HIGH | PHPGurukul Blood Bank & Donor Management System request-received-bydonar.php sql injection |
| CVE-2025-4154 | 6.3 MEDIUM | PHPGurukul Pre-School Enrollment System enrollment-details.php sql injection |
| CVE-2025-4155 | 6.3 MEDIUM | PHPGurukul Boat Booking System edit-boat.php sql injection |
| CVE-2025-4156 | 6.3 MEDIUM | PHPGurukul Boat Booking System change-image.php sql injection |
| CVE-2025-4157 | 6.3 MEDIUM | PHPGurukul Boat Booking System booking-details.php sql injection |
| CVE-2025-4163 | 6.3 MEDIUM | PHPGurukul Land Record System aboutus.php sql injection |
No comments yet