CVE-2025-45947

CRITICAL

Phpgurukul Online Banquet Booking System - Code Injection

Title source: rule

Description

An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the My Account - Change Password component

Exploits (1)

github WRITEUP
by VasilVK · poc
https://github.com/VasilVK/CVE/tree/main/CVE-2025-45947

Scores

CVSS v3 9.8
EPSS 0.0130
EPSS Percentile 79.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (1)
phpgurukul/online_banquet_booking_system 1.2
Published Apr 28, 2025
Tracked Since Feb 18, 2026