CVE-2025-2034
published 2025-03-06CVE-2025-2034: A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this vulnerability is an unknown…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.48%
38.7th percentile
A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-class.php?cid=1. The manipulation of the argument classname/capacity/classtiming leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phpgurukul | pre-school_enrollment_system | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-24143 webkitgtk: A maliciously crafted webpage may be able to fingerprint the user
bugzilla·2025-02-10·CVSS 6.5
CVE-2025-24143 [MEDIUM] CVE-2025-24143 webkitgtk: A maliciously crafted webpage may be able to fingerprint the user
CVE-2025-24143 webkitgtk: A maliciously crafted webpage may be able to fingerprint the user
The issue was addressed with improved access restrictions to the file system. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, visionOS 2.3. A maliciously crafted webpage may be able to fingerprint the user.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:2035 https://access.redhat.com/errata/RHSA-2025:2035
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:2034 https://access.redhat.com/errata/RHSA-2025:2034
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7 Extended Lifecycle Support
Via RHSA-2025:10364 h
Bugzilla
CVE-2025-24150 webkitgtk: Copying a URL from Web Inspector may lead to command injection
bugzilla·2025-02-10·CVSS 8.8
CVE-2025-24150 [HIGH] CVE-2025-24150 webkitgtk: Copying a URL from Web Inspector may lead to command injection
CVE-2025-24150 webkitgtk: Copying a URL from Web Inspector may lead to command injection
A privacy issue was addressed with improved handling of files. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Copying a URL from Web Inspector may lead to command injection.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:2035 https://access.redhat.com/errata/RHSA-2025:2035
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:2034 https://access.redhat.com/errata/RHSA-2025:2034
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7 Extended Lifecycle Support
Via RHSA-2025:10364 https://access.redhat.com/errata/RHS
Bugzilla
CVE-2025-24158 webkitgtk: Processing web content may lead to a denial-of-service
bugzilla·2025-02-10·CVSS 6.5
CVE-2025-24158 [MEDIUM] CVE-2025-24158 webkitgtk: Processing web content may lead to a denial-of-service
CVE-2025-24158 webkitgtk: Processing web content may lead to a denial-of-service
The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing web content may lead to a denial-of-service.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:2035 https://access.redhat.com/errata/RHSA-2025:2035
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:2034 https://access.redhat.com/errata/RHSA-2025:2034
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7 Extended Lifecycle Support
Via RHSA-2025:10364 https://access.redhat
2025-03-06
Published