CVE-2025-28011

Publication date

2025-03-13 00:00:00

Family

mitre

State

PUBLISHED

Description

A SQL Injection was found in loginsystem/change-password.php in PHPGurukul User Registration & Login and User Management System v3.3 allows remote attackers to execute arbitrary code via the currentpassword POST request parameter.