CVE-2025-45947Code Injection in Online Banquet Booking System

CWE-94Code Injection3 documents3 sources
Severity
9.8CRITICALNVD
EPSS
1.3%
top 20.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 28

Description

An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the My Account - Change Password component

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
CVE-2025-45947: An issue in phpgurukul Online Banquet Booking System V12025-04-28
GHSA
GHSA-rwf8-w7mh-r554: An issue in phpgurukul Online Banquet Booking System V12025-04-28
CVE-2025-45947 — Code Injection | cvebase