CVE-2025-9829

A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /signup.php. The manipulation of the argument mobilenumber leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. Other parameters might be affected as well.
References
Link Resource
https://github.com/dad-zm/myCVE/issues/4 Exploit Third Party Advisory Issue Tracking
https://phpgurukul.com/ Product
https://vuldb.com/?ctiid.322176 Press/Media Coverage VDB Entry
https://vuldb.com/?id.322176 Third Party Advisory VDB Entry
https://vuldb.com/?submit.641587 Third Party Advisory VDB Entry
https://vuldb.com/?submit.641592 Third Party Advisory VDB Entry
https://vuldb.com/?submit.641595 Third Party Advisory VDB Entry
https://github.com/dad-zm/myCVE/issues/4 Exploit Third Party Advisory Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpgurukul:beauty_parlour_management_system:1.1:*:*:*:*:*:*:*

History

05 Sep 2025, 18:03

Type Values Removed Values Added
References () https://github.com/dad-zm/myCVE/issues/4 - () https://github.com/dad-zm/myCVE/issues/4 - Exploit, Third Party Advisory, Issue Tracking
References () https://phpgurukul.com/ - () https://phpgurukul.com/ - Product
References () https://vuldb.com/?ctiid.322176 - () https://vuldb.com/?ctiid.322176 - Press/Media Coverage, VDB Entry
References () https://vuldb.com/?id.322176 - () https://vuldb.com/?id.322176 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.641587 - () https://vuldb.com/?submit.641587 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.641592 - () https://vuldb.com/?submit.641592 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.641595 - () https://vuldb.com/?submit.641595 - Third Party Advisory, VDB Entry
First Time Phpgurukul beauty Parlour Management System
Phpgurukul
CPE cpe:2.3:a:phpgurukul:beauty_parlour_management_system:1.1:*:*:*:*:*:*:*

02 Sep 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-02 19:15

Updated : 2025-09-05 18:03


NVD link : CVE-2025-9829

Mitre link : CVE-2025-9829

CVE.ORG link : CVE-2025-9829


JSON object : View

Products Affected

phpgurukul

  • beauty_parlour_management_system
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')