CVE-2025-25357
CVSS 3.1 Score 7.2 of 10 (high)
Details
Summary
CVE-2025-25357 is a SQL Injection vulnerability that affects the /admin/contactus.php file in the PHPGurukul Land Record System v1.0. Attackers can exploit this weakness by sending a maliciously crafted email POST request to the server, allowing them to inject and execute arbitrary SQL code. This vulnerability poses a serious threat, potentially granting attackers unauthorized access to sensitive data or even the ability to make modifications to the system. It is crucial that users of this software update to a patch or a more secure version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Phpgurukul Land Record System
Affected Vendors
- Phpgurukul