CVE-2025-2678

CVSS 3.1 Score 8.4 of 10 (high)

Details

Published Mar 24, 2025
Updated: Mar 26, 2025
CWE ID 639

Summary

CVE-2025-2678 is a critical vulnerability discovered in the PHPGurukul Bank Locker Management System 1.0. The issue lies in an unspecified part of the file /changeimage1.php where an sql injection vulnerability arises due to the manipulation of the editid argument. This flaw can be exploited remotely, allowing attackers to execute malicious SQL queries and potentially gain unauthorized access to sensitive data or even take control of the system. The exploit for this vulnerability has been made public, increasing the risk for potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share