CVE-2025-4861 | PHPGurukul Beauty Parlour Management System 1.1 /admin/admin-profile.php contactnumber sql injection
A vulnerability classified as critical was found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument contactnumber leads to sql injection.
This vulnerability is known as CVE-2025-4861. The attack can be launched remotely. Furthermore, there is an exploit available.
Other parameters might be affected as well.