CVE-2025-4308
published 2025-05-06CVE-2025-4308: A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been declared as critical. Affected by this vulnerability is an unknown…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.50%
39.4th percentile
A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add-art-type.php. The manipulation of the argument arttype leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phpgurukul | art_gallery_management_system | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
cisa8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-35fx-99jc-mf6j: A vulnerability was found in PHPGurukul Art Gallery Management System 1
ghsa_unreviewed·2025-05-06
CVE-2025-4308 [MEDIUM] CWE-74 GHSA-35fx-99jc-mf6j: A vulnerability was found in PHPGurukul Art Gallery Management System 1
A vulnerability was found in PHPGurukul Art Gallery Management System 1.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add-art-type.php. The manipulation of the argument arttype leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CISA
TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability
cisa·2025-09-03·CVSS 6.5
CVE-2023-50224 [MEDIUM] CWE-290 TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability
Vulnerability: TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability
Affected: TP-Link TL-WR841N
TP-Link TL-WR841N contains an authentication bypass by spoofing vulnerability within the httpd service, which listens on TCP port 80 by default, leading to the disclose of stored credentials. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://www.tp-link.com/us/support/faq/4308/ ; https://nvd.nist.gov/vuln/detail/CVE-2023-50224
Remediation Due Date: 2025-09-24
CISA
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability
cisa·2025-09-03·CVSS 8.6
CVE-2025-9377 [HIGH] CWE-78 TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability
Vulnerability: TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability
Affected: TP-Link Multiple Routers
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Control page. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://www.tp-link.com/us/support/faq/4308/ ; https://nvd.nist.gov/vuln/detail/CVE-2025-9377
Remediation Due Date: 2025-09-24
No detection rules found.
No public exploits indexed.
2025-05-06
Published