CVE-2025-1906
Last modified
CVE-2025-1906 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability has been found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
A vulnerability has been found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phpgurukul | Restaurant Table Booking System | 1.0 |
References
- https://github.com/HaroldFinch-L/CVE/issues/2Exploit, Issue Tracking
- https://phpgurukul.com/Product
- https://vuldb.com/?ctiid.298426Permissions Required
- https://vuldb.com/?id.298426Permissions Required
- https://vuldb.com/?submit.508915Third Party Advisory
- https://github.com/HaroldFinch-L/CVE/issues/2Exploit, Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-1906?
How severe is CVE-2025-1906?
How do I fix CVE-2025-1906?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-1900A vulnerability was found in PHPGurukul Restaurant Table Boo…9.8
- CVE-2025-1901A vulnerability was found in PHPGurukul Restaurant Table Boo…9.8
- CVE-2025-1902A vulnerability was found in PHPGurukul Student Record Syste…9.8
- CVE-2025-1903A vulnerability was found in Codezips Online Shopping Websit…9.8
- CVE-2025-1904A vulnerability, which was classified as problematic, has be…6.1
- CVE-2025-1905A vulnerability, which was classified as problematic, was fo…6.1
- CVE-2025-1907Instantel Micromate lacks authentication on a configuration …9.8
- CVE-2025-1908An issue has been discovered in GitLab EE/CE that could allo…7.7
- CVE-2025-1909The BuddyBoss Platform Pro plugin for WordPress is vulnerabl…9.8
- CVE-2025-1910The WatchGuard Mobile VPN with SSL Client on Windows allows …6.3
- CVE-2025-1911The Product Import Export for WooCommerce – Import Export Pr…6.5
- CVE-2025-1912The Product Import Export for WooCommerce – Import Export Pr…7.6
Are you affected by CVE-2025-1906?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
