CVE-2025-11053

CWE-74CWE-89SQL Injection7 documents6 sources
Severity
6.9MEDIUM
EPSS
0.0%
top 92.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 27

Description

A weakness has been identified in PHPGurukul Small CRM 4.0. This affects an unknown function of the file /forgot-password.php. Executing manipulation of the argument email can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-g4r8-9p96-4rpc: A weakness has been identified in PHPGurukul Small CRM 42025-09-27
CVEList
PHPGurukul Small CRM forgot-password.php sql injection2025-09-27

📋Vendor Advisories

3
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (curl) — CVE-2024-110532025-04-15
Oracle
Oracle Oracle MySQL Risk Matrix: Enterprise Backup (curl) — CVE-2024-110532025-01-15
Microsoft
netrc and redirect credential leak2024-12-10

💬Community

1
HackerOne
CVE-2025-0167: netrc and default credential leak2025-02-07
CVE-2025-11053 (MEDIUM CVSS 6.9) | A weakness has been identified in P | cvebase.io