CVE-2025-1906

A

vulnerability has been found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

References
Link Resource
https://github.com/HaroldFinch-L/CVE/issues/2 Exploit Issue Tracking
https://phpgurukul.com/ Product
https://vuldb.com/?ctiid.298426 Permissions Required
https://vuldb.com/?id.298426 Permissions Required
https://vuldb.com/?submit.508915 Third Party Advisory
https://github.com/HaroldFinch-L/CVE/issues/2 Exploit Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpgurukul:restaurant_table_booking_system:1.0:*:*:*:*:*:*:*

History

06 Mar 2025, 12:17

Type Values Removed Values Added
References () https://github.com/HaroldFinch-L/CVE/issues/2 - () https://github.com/HaroldFinch-L/CVE/issues/2 - Exploit, Issue Tracking
References () https://phpgurukul.com/ - () https://phpgurukul.com/ - Product
References () https://vuldb.com/?ctiid.298426 - () https://vuldb.com/?ctiid.298426 - Permissions Required
References () https://vuldb.com/?id.298426 - () https://vuldb.com/?id.298426 - Permissions Required
References () https://vuldb.com/?submit.508915 - () https://vuldb.com/?submit.508915 - Third Party Advisory
First Time Phpgurukul
Phpgurukul restaurant Table Booking System
CPE cpe:2.3:a:phpgurukul:restaurant_table_booking_system:1.0:*:*:*:*:*:*:*
Summary
  • (es) Se ha encontrado una vulnerabilidad en PHPGurukul Restaurant Table Booking System 1.0 y se ha clasificado como crítica. Esta vulnerabilidad afecta al código desconocido del archivo /admin/profile.php. La manipulación del argumento mobilenumber conduce a una inyección SQL. El ataque se puede iniciar de forma remota. La vulnerabilidad se ha hecho pública y puede utilizarse. También pueden verse afectados otros parámetros.

04 Mar 2025, 15:15

Type Values Removed Values Added
References () https://github.com/HaroldFinch-L/CVE/issues/2 - () https://github.com/HaroldFinch-L/CVE/issues/2 -

04 Mar 2025, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-04 05:15

Updated : 2025-03-06 12:17


NVD link : CVE-2025-1906

Mitre link : CVE-2025-1906

CVE.ORG link : CVE-2025-1906


JSON object : View

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')