CVE-2025-3370

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Apr 7, 2025
CWE ID 74
CWE ID 89

Summary

CVE-2025-3370 is a newly discovered critical vulnerability in the PHPGurukul Men Salon Management System 1.0. The issue lies within the /admin/admin-profile.php file and involves the contactnumber argument. An attacker can exploit this vulnerability through sql injection, allowing them to manipulate the data and potentially gain unauthorized access. The exploit is publicly disclosed, increasing the risk of remote attacks. It's important to note that other parameters might also be susceptible to similar attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share