CVE-2025-7591
published 2025-07-14CVE-2025-7591: A vulnerability, which was classified as critical, was found in PHPGurukul Dairy Farm Shop Management System 1.3. Affected is an unknown function of the file…
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.32%
23.4th percentile
A vulnerability, which was classified as critical, was found in PHPGurukul Dairy Farm Shop Management System 1.3. Affected is an unknown function of the file view-invoice.php. The manipulation of the argument invid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phpgurukul | dairy_farm_shop_management_system | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS Progress Kemp LoadMaster Unauthenticated Command Injection (CVE-2024-7591)
suricata·2025-05-13·CVSS 10.0
CVE-2024-7591 [CRITICAL] ET WEB_SPECIFIC_APPS Progress Kemp LoadMaster Unauthenticated Command Injection (CVE-2024-7591)
ET WEB_SPECIFIC_APPS Progress Kemp LoadMaster Unauthenticated Command Injection (CVE-2024-7591)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Progress Kemp LoadMaster Unauthenticated Command Injection (CVE-2024-7591)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/progs/status/login"; fast_pattern; http.request_body; content:"pass|3d|"; pcre:"/^[^\x26\s]*?(?:[\x3b\x24\x27\x60\x7c]|\x25(?:3[bB]|2[47]|60|7[cC]))/R"; reference:url,insinuator.net/2024/11/vulnerability-disclosure-command-injection-in-kemp-loadmaster-load-balancer-cve-2024-7591; reference:cve,2024-7591; classtype:web-application-attack; sid:2062294; rev:1; metadata:affected_product Progress_Kemp_Loadmaster, attack_target Server, created_at 2025_05_13, cve CVE_2024_7591, depl
No public exploits indexed.
No writeups or analysis indexed.
2025-07-14
Published