Beveiligingsadvies

CVE-2025-25354

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-02-13 00:00:00
Laatst bijgewerkt 2025-02-14 19:06:53
Toegewezen door mitre
CVSS-score 7.2
Status PUBLISHED

Beschrijving

A SQL Injection was found in /admin/admin-profile.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the contactnumber POST request parameter.