Home

Description

A time-based blind SQL injection vulnerability was identified in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability exists in the manage-companies.php file and allows remote attackers to execute arbitrary SQL code via the companyname parameter in a POST request.

PUBLISHED Reserved 2025-06-16 | Published 2025-06-26 | Updated 2025-06-26 | Assigner mitre

References

github.com/...ement-System/SQL/SQL_injection_edit-company.md

cve.org (CVE-2025-51672)

nvd.nist.gov (CVE-2025-51672)

Download JSON