CVE-2025-4005

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 28, 2025
Updated: May 12, 2025
CWE ID 89
CWE ID 74

Summary

CVE-2025-4015 exposes a critical sql injection vulnerability in the PHPGurukul COVID19 Testing Management System 1.0. The vulnerability, which affects the processing of the /patient-report.php file, can be exploited by manipulating the argument searchdata. Successful attacks can be initiated remotely, making this issue a significant security concern. The exploit for this vulnerability has been made public, increasing the risk of widespread exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share