Security Advisory

CVE-2025-28011

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-03-13 00:00:00
Last updated 2025-03-19 18:43:30
Assigner mitre
State PUBLISHED

Description

A SQL Injection was found in loginsystem/change-password.php in PHPGurukul User Registration & Login and User Management System v3.3 allows remote attackers to execute arbitrary code via the currentpassword POST request parameter.