github.comexploitissue tracking
https://github.com/f1rstb100d/myCVE/issues/30 CVE-2025-5553
MEDIUM
PHPGurukul Rail Pass Management System download-pass.php sql injection
Record summary
CVE-2025-5553 has a selected CVSS score of 6.9 (medium); EIP currently links 1 catalogued exploit.
Description
A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /download-pass.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Rail Pass Management SystemBrowse PHPGurukul / Rail Pass Management System | CVE List | 1.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBRail Pass Management System 1.0 - Time-Based SQL InjectionExploitDB exploitby yozgatalperen1Not analyzed1 file
References
7nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-5553 phpgurukul.comproduct
https://phpgurukul.com/ VDB-311005 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/?ctiid.311005 VDB-311005 | PHPGurukul Rail Pass Management System download-pass.php sql injectionvdb entryTechnical description
https://vuldb.com/?id.311005 Submit #587416 | PHPGurukul Rail Pass Management System 1.0 SQL InjectionThird-party advisory
https://vuldb.com/?submit.587416 exploit-db.com
https://www.exploit-db.com/exploits/51790