← Back to CVE List

CVE-2025-28011

Published: 2025-03-13T17:15Z
Last Modified: 2025-03-28T20:00Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A SQL Injection was found in loginsystem/change-password.php in PHPGurukul User Registration & Login and User Management System v3.3 allows remote attackers to execute arbitrary code via the currentpassword POST request parameter. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt