CVE-2025-3370
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Apr 7, 2025
CWE ID 74
CWE ID 89
Summary
CVE-2025-3370 is a newly discovered critical vulnerability in the PHPGurukul Men Salon Management System 1.0. The issue lies within the /admin/admin-profile.php file and involves the contactnumber argument. An attacker can exploit this vulnerability through sql injection, allowing them to manipulate the data and potentially gain unauthorized access. The exploit is publicly disclosed, increasing the risk of remote attacks. It's important to note that other parameters might also be susceptible to similar attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.