CVE-2025-2676

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 24, 2025
Updated: Mar 26, 2025
CWE ID 502

Summary

CVE-2025-2676 is a critical vulnerability affecting the PHPGurukul Bank Locker Management System 1.0. The issue lies in an unspecified part of the file "/add-subadmin.php," where an SQL injection vulnerability can be triggered by manipulating the "sadminusername" argument. An attacker can exploit this remotely, making the threat significant and public disclosure of the exploit increases the risk for potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share