A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/check_availability.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://github.com/chenzi-dynasty/CVE/issues/1 | Exploit Issue Tracking |
https://github.com/chenzi-dynasty/CVE/issues/1 | Exploit Issue Tracking |
https://phpgurukul.com/ | Product |
https://vuldb.com/?ctiid.298419 | Permissions Required |
https://vuldb.com/?id.298419 | Third Party Advisory |
https://vuldb.com/?submit.506612 | Exploit Third Party Advisory |
Configurations
History
06 Mar 2025, 12:21
Type | Values Removed | Values Added |
---|---|---|
First Time |
Phpgurukul restaurant Table Booking System
Phpgurukul |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
References | () https://phpgurukul.com/ - Product | |
References | () https://vuldb.com/?id.298419 - Third Party Advisory | |
References | () https://github.com/chenzi-dynasty/CVE/issues/1 - Exploit, Issue Tracking | |
References | () https://vuldb.com/?ctiid.298419 - Permissions Required | |
References | () https://vuldb.com/?submit.506612 - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:phpgurukul:restaurant_table_booking_system:1.0:*:*:*:*:*:*:* |
04 Mar 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-74 |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
04 Mar 2025, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-04 04:15
Updated : 2025-03-06 12:21
NVD link : CVE-2025-1901
Mitre link : CVE-2025-1901
JSON object : View
Products Affected
phpgurukul
- restaurant_table_booking_system
CWE
No CWE.