CVE-2025-4263
published 2025-05-05CVE-2025-4263: A vulnerability was found in PHPGurukul Online DJ Booking Management System 1.0. It has been rated as critical. This issue affects some unknown processing of…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.43%
34.6th percentile
A vulnerability was found in PHPGurukul Online DJ Booking Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/booking-search.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phpgurukul | online_dj_booking_management_system | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-11233 php: Single byte overread with convert.quoted-printable-decode filter
bugzilla·2024-11-24·CVSS 8.2
CVE-2024-11233 [HIGH] CVE-2024-11233 php: Single byte overread with convert.quoted-printable-decode filter
CVE-2024-11233 php: Single byte overread with convert.quoted-printable-decode filter
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.
Discussion:
Is there a status update as to when this will be patched for, or PHP moved to 8.1.31, please?
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:4263 https://access.redhat.com/errata/RHSA-2025:4263
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:7315 https://access.redhat.com/errata/RHSA-2025:7315
--
Bugzilla
CVE-2024-11234 php: Configuring a proxy in a stream context might allow for CRLF injection in URIs
bugzilla·2024-11-24·CVSS 7.2
CVE-2024-11234 [HIGH] CVE-2024-11234 php: Configuring a proxy in a stream context might allow for CRLF injection in URIs
CVE-2024-11234 php: Configuring a proxy in a stream context might allow for CRLF injection in URIs
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option, the URI is not properly sanitized which can lead to HTTP request smuggling and allow the attacker to use the proxy to perform arbitrary HTTP requests originating from the server, thus potentially gaining access to resources not normally available to the external user.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:4263 https://access.redhat.com/errata/RHSA-2025:4263
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:7315 htt
2025-05-05
Published