A vulnerability classified as critical has been found in PHPGurukul Company Visitor Management System 2.0. Affected is an unknown function of the file /admin-profile.php. The manipulation of the argument adminname/mobilenumber leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/Pjwww13447/pjwww/issues/2 | Exploit Third Party Advisory Issue Tracking |
| https://phpgurukul.com/ | Product |
| https://vuldb.com/?ctiid.307476 | Permissions Required VDB Entry |
| https://vuldb.com/?id.307476 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.564733 | Third Party Advisory VDB Entry |
| https://github.com/Pjwww13447/pjwww/issues/2 | Exploit Third Party Advisory Issue Tracking |
Configurations
History
30 Sep 2025, 15:49
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/Pjwww13447/pjwww/issues/2 - Exploit, Third Party Advisory, Issue Tracking | |
| References | () https://vuldb.com/?ctiid.307476 - Permissions Required, VDB Entry |
15 May 2025, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-05-06 14:15
Updated : 2025-09-30 15:49
NVD link : CVE-2025-4358
Mitre link : CVE-2025-4358
CVE.ORG link : CVE-2025-4358
JSON object : View
Products Affected
phpgurukul
- company_visitor_management_system
