CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-4917: PHPGurukul Auto Taxi Stand Management System new-autoortaxi-entry-form.php sql injection

7.3 CVSS

Description

A vulnerability classified as critical has been found in PHPGurukul Auto Taxi Stand Management System 1.0. Affected is an unknown function of the file /admin/new-autoortaxi-entry-form.php. The manipulation of the argument drivername leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. Es wurde eine kritische Schwachstelle in PHPGurukul Auto Taxi Stand Management System 1.0 entdeckt. Betroffen hiervon ist ein unbekannter Ablauf der Datei /admin/new-autoortaxi-entry-form.php. Dank der Manipulation des Arguments drivername mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung.

Classification

CVE ID: CVE-2025-4917

CVSS Base Severity: HIGH

CVSS Base Score: 7.3

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Problem Types

SQL Injection Injection

Affected Products

Vendor: PHPGurukul

Product: Auto Taxi Stand Management System

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.03% (probability of being exploited)

EPSS Percentile: 6.72% (scored less or equal to compared to others)

EPSS Date: 2025-06-17 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-4917
https://vuldb.com/?id.309474
https://vuldb.com/?ctiid.309474
https://vuldb.com/?submit.579100
https://github.com/Pjwww13447/pjwww/issues/19
https://phpgurukul.com/

Timeline