CVE-2025-45020

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Apr 30, 2025
Updated: May 9, 2025
CWE ID 89

Summary

CVE-2025-45020 is a newly disclosed SQL Injection vulnerability that affects the PHPGurukul Park Ticketing Management System version 2.0. The issue lies in the normal-bwdates-reports-details.php file and can be exploited through a maliciously crafted POST request targeting the todate parameter. Successful attacks could allow remote adversaries to execute arbitrary SQL code and potentially gain unauthorized access to sensitive data or even take control of the underlying database. This vulnerability poses a serious risk to organizations utilizing this system and underscores the importance of timely software updates and secure coding practices.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share