A SQL injection vulnerability was discovered in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability allows remote attackers to execute arbitrary SQL code via the category and categorycode parameters in a POST request to the manage-categories.php file.
History

Tue, 01 Jul 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Phpgurukul
Phpgurukul dairy Farm Shop Management System
CPEs cpe:2.3:a:phpgurukul:dairy_farm_shop_management_system:1.3:*:*:*:*:*:*:*
Vendors & Products Phpgurukul
Phpgurukul dairy Farm Shop Management System

Thu, 26 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 26 Jun 2025 15:30:00 +0000

Type Values Removed Values Added
Description A SQL injection vulnerability was discovered in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability allows remote attackers to execute arbitrary SQL code via the category and categorycode parameters in a POST request to the manage-categories.php file.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-06-26T00:00:00.000Z

Updated: 2025-06-26T19:56:03.068Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-51671

cve-icon Vulnrichment

Updated: 2025-06-26T19:55:57.518Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-26T16:15:31.147

Modified: 2025-07-01T15:53:21.097

Link: CVE-2025-51671

cve-icon Redhat

No data.