VYPR

Php Gurukul Billing System

Sign in to watch

by Pachno

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2025-653790.000.00Dec 2, 2025PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically, the username and mobileno parameters accepts unvalidated user input, which is then concatenated directly into a backend SQL query.
CVE-2025-653800.000.00Dec 2, 2025PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username parameter accepts unvalidated user input, which is then concatenated directly into a backend SQL query.