1 results (0.006 seconds)
CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

CVE-2025-1902 – PHPGurukul Student Record System password-recovery.php sql injection
https://notcve.org/view.php?id=CVE-2025-1902
04 Mar 2025 — A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability affects unknown code of the file /password-recovery.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely. • https://github.com/panghuanjie/Code-audits/issues/3 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •