A vulnerability was identified in PHPGurukul Online Discussion Forum 1.0. This affects an unknown part of the file /admin/edit_member.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
History

Thu, 18 Sep 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Emiloi
Emiloi online Discussion Forum
CPEs cpe:2.3:a:emiloi:online_discussion_forum:1.0:*:*:*:*:*:*:*
Vendors & Products Emiloi
Emiloi online Discussion Forum

Thu, 18 Sep 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Phpgurukul
Phpgurukul online Discussion Forum
Vendors & Products Phpgurukul
Phpgurukul online Discussion Forum

Wed, 17 Sep 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 17 Sep 2025 17:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in PHPGurukul Online Discussion Forum 1.0. This affects an unknown part of the file /admin/edit_member.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
Title PHPGurukul Online Discussion Forum edit_member.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-09-17T17:32:07.195Z

Updated: 2025-09-17T19:50:18.518Z

Reserved: 2025-09-17T07:00:12.300Z

Link: CVE-2025-10604

cve-icon Vulnrichment

Updated: 2025-09-17T19:50:08.356Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-17T18:15:42.373

Modified: 2025-09-18T20:22:51.310

Link: CVE-2025-10604

cve-icon Redhat

No data.