CVE-2025-51671 — SQL Injection in Dairy Farm Shop Management System

CWE-89 — SQL Injection3 documents3 sources
Severity
5.4MEDIUMNVD
EPSS
0.1%
top 78.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 26

Description

A SQL injection vulnerability was discovered in the PHPGurukul Dairy Farm Shop Management System 1.3. The vulnerability allows remote attackers to execute arbitrary SQL code via the category and categorycode parameters in a POST request to the manage-categories.php file.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
CVE-2025-51671: A SQL injection vulnerability was discovered in the PHPGurukul Dairy Farm Shop Management System 1↗2025-06-26
â–¶
GHSA
GHSA-462q-5hcm-pmww: A SQL injection vulnerability was discovered in the PHPGurukul Dairy Farm Shop Management System 1↗2025-06-26
â–¶
CVE-2025-51671 — SQL Injection | cvebase