Description
A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edit-user.php. The manipulation results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.
Problem types
Product status
Timeline
| 2025-12-31: | Advisory disclosed |
| 2025-12-31: | VulDB entry created |
| 2025-12-31: | VulDB entry last update |
Credits
hackerfactory (VulDB User)
References
vuldb.com/?id.339151 (VDB-339151 | PHPGurukul Small CRM edit-user.php authorization)
vuldb.com/?ctiid.339151 (VDB-339151 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.727430 (Submit #727430 | PHPGurukul PHPGurukul Small Customer Relationship Management v4.0 Missing Authorization)
github.com/...-CRM-in-PHP/blob/main/Broken Access Control.md
phpgurukul.com/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.