CVE-2025-4911Injection in ZOO Management System

Severity
6.9MEDIUMNVD
EPSS
0.3%
top 48.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 19
Latest updateFeb 11

Description

A vulnerability, which was classified as critical, was found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/view-foreigner-ticket.php. The manipulation of the argument viewid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
PHPGurukul Zoo Management System view-foreigner-ticket.php sql injection2025-05-19
GHSA
GHSA-78rf-57vv-hcw9: A vulnerability, which was classified as critical, was found in PHPGurukul Zoo Management System 22025-05-19

💥Exploits & PoCs

1
Exploit-DB
glibc 2.38 - Buffer Overflow2026-02-11

📋Vendor Advisories

1
Microsoft
Glibc: buffer overflow in ld.so leading to privilege escalation2023-10-10
CVE-2025-4911 — Injection in ZOO Management System | cvebase