CVE-2025-4005
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 28, 2025
Updated: May 12, 2025
CWE ID 89
CWE ID 74
Summary
CVE-2025-4015 exposes a critical sql injection vulnerability in the PHPGurukul COVID19 Testing Management System 1.0. The vulnerability, which affects the processing of the /patient-report.php file, can be exploited by manipulating the argument searchdata. Successful attacks can be initiated remotely, making this issue a significant security concern. The exploit for this vulnerability has been made public, increasing the risk of widespread exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.