CVE-2025-28011 | PHPGurukul User Registration & Login and User Management System POST Request Parameter change-password.php sql injection
A vulnerability classified as critical was found in PHPGurukul User Registration & Login and User Management System 3.3. This vulnerability affects unknown code of the file loginsystem/change-password.php of the component POST Request Parameter Handler. The manipulation of the argument currentpassword leads to sql injection.
This vulnerability was named CVE-2025-28011. The attack can be initiated remotely. There is no exploit available.