PHPGurukul News Portal是PHPGurukul公司的一个新闻门户网站。 PHPGurukul News Portal 4.1版本存在安全漏洞,该漏洞源于文件/admin/forgot-password.php中对参数Username的错误操作导致SQL注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PHPGurukul | News Portal | 4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2025-5367 | 7.3 HIGH | PHPGurukul Online Shopping Portal Project category.php sql injection |
| CVE-2025-5375 | 6.3 MEDIUM | PHPGurukul HPGurukul Online Birth Certificate System registered-users.php sql injection |
| CVE-2025-5374 | 6.3 MEDIUM | PHPGurukul Online Birth Certificate System all-applications.php sql injection |
| CVE-2025-5373 | 6.3 MEDIUM | PHPGurukul Online Birth Certificate System users-applications.php sql injection |
| CVE-2025-5368 | 6.3 MEDIUM | PHPGurukul Daily Expense Tracker System expense-yearwise-reports-detailed.php sql injectio |
No comments yet