CVE-2025-2676
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 24, 2025
Updated: Mar 26, 2025
CWE ID 502
Summary
CVE-2025-2676 is a critical vulnerability affecting the PHPGurukul Bank Locker Management System 1.0. The issue lies in an unspecified part of the file "/add-subadmin.php," where an SQL injection vulnerability can be triggered by manipulating the "sadminusername" argument. An attacker can exploit this remotely, making the threat significant and public disclosure of the exploit increases the risk for potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.