CVE-2025-28011

MEDIUM

PHPGurukul User Registration & Login and User Management System v3.3 - SQL Injection via currentpassword Parameter

Title source: llm
STIX 2.1

Description

A SQL Injection was found in loginsystem/change-password.php in PHPGurukul User Registration & Login and User Management System v3.3 allows remote attackers to execute arbitrary code via the currentpassword POST request parameter.

Scores

CVSS v3 6.1
EPSS 0.0031
EPSS Percentile 54.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
phpgurukul/user_registration_\&_login_and_user_management_system 3.3
Published Mar 13, 2025
Tracked Since Feb 18, 2026