Security Advisory

CVE-2025-25389

9.8
CRITICAL

Vulnerability Description

A SQL Injection vulnerability was found in /admin/forgot-password.php in Phpgurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the contactno POST request parameter.
Published Date February 13, 2025
Official Source NIST NVD Advisory