CVE-2025-45947

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 28, 2025
Updated: Apr 30, 2025
CWE ID 94

Summary

CVE-2025-45947 is a vulnerability affecting the phpgurukul Online Banquet Booking System V1.2. This issue enables attackers to execute arbitrary code through the /obbs/change-password.php file in the My Account - Change Password component. By exploiting this vulnerability, an attacker can gain unauthorized access and potentially take control of the system. This could lead to data theft, manipulation, or even system destruction. Users are advised to upgrade to the latest version of the software or apply the vendor-provided patch as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Phpgurukul Online Banquet Booking System

Affected Vendors

  • Phpgurukul