CVE-2025-3690
Last modified
CVE-2025-3690 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/edit-services.php. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/edit-services.php. The manipulation of the argument cost leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phpgurukul | Men Salon Management System | 1.0 |
References
- https://github.com/Xiaoyao-i03i/CVE/issues/2Exploit, Third Party Advisory
- https://phpgurukul.com/Product
- https://vuldb.com/?ctiid.304979Permissions Required, VDB Entry
- https://vuldb.com/?id.304979Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.553501Third Party Advisory, VDB Entry
- https://github.com/Xiaoyao-i03i/CVE/issues/2Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-3690?
How severe is CVE-2025-3690?
How do I fix CVE-2025-3690?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-36894In TBD of TBD, there is a possible DoS due to a missing null…7.5
- CVE-2025-36895Information disclosure7.5
- CVE-2025-36896WLAN in Android before 2025-09-05 on Google Pixel devices al…9.8
- CVE-2025-36897In unknown of cd_CnMsgCodecUserApi.cpp, there is a possible …9.8
- CVE-2025-36898There is a possible escalation of privilege due to a logic e…7.8
- CVE-2025-36899There is a possible escalation of privilege due to test/debu…8.4
- CVE-2025-36900In lwis_test_register_io of lwis_device_test.c, there is a p…6.7
- CVE-2025-36901WLAN in Android before 2025-09-05 on Google Pixel devices al…8.8
- CVE-2025-36902In syna_cdev_ioctl_store_pid() of syna_tcm2_sysfs.c, there i…6.7
- CVE-2025-36903In lwis_io_buffer_write, there is a possible OOB read/write …7.8
- CVE-2025-36904WLAN in Android before 2025-09-05 on Google Pixel devices al…9.8
- CVE-2025-36905In gxp_mapping_create of gxp_mapping.c, there is a possible …7.8
Are you affected by CVE-2025-3690?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
