A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2.0. The vulnerability is due to lack of input validation of multiple parameters including fullname, email, and contactno in user/registration.php.
References
| Link | Resource |
|---|---|
| https://doc.clickup.com/3897127/p/h/3pxt7-12556/5435bb675762866 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-09-03 15:15
Updated : 2025-09-08 17:18
NVD link : CVE-2025-57147
Mitre link : CVE-2025-57147
CVE.ORG link : CVE-2025-57147
JSON object : View
Products Affected
phpgurukul
- complaint_management_system
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
