Search

published date: April 28, 2025

CVE-2025-4039 : SQL Injection Vulnerability

Description

A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/search-pass.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Product(s):

  • PHPGurukul Rail Pass Management System 1.0

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2025-4039, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2025-4039 in your products or services, and how will you communicate updates on this issue to us as your customer?

References:

READY TO GET RESULTS YOU CAN TRUST?