CVE-2025-28011
CVE-2025-28011
Título es
CVE-2025-28011
Jue, 13/03/2025 – 17:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-28011
Descripción en
A SQL Injection was found in loginsystem/change-password.php in PHPGurukul User Registration & Login and User Management System v3.3 allows remote attackers to execute arbitrary code via the currentpassword POST request parameter.
13/03/2025
13/03/2025
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
https://github.com/rtnthakur/CVE/blob/main/PHPGurukul/User%20Registration%20%26%20Login%20and%20User%20Management%20System%20With%20admin%20panel/Change-password-sql-injection.pdf
Enviar en el boletín
Off
