CVE-2025-45947
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-45947 is a vulnerability affecting the phpgurukul Online Banquet Booking System V1.2. This issue enables attackers to execute arbitrary code through the /obbs/change-password.php file in the My Account - Change Password component. By exploiting this vulnerability, an attacker can gain unauthorized access and potentially take control of the system. This could lead to data theft, manipulation, or even system destruction. Users are advised to upgrade to the latest version of the software or apply the vendor-provided patch as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Phpgurukul Online Banquet Booking System
Affected Vendors
- Phpgurukul