A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /registered-user-testing.php. The manipulation of the argument testtype leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
History

Tue, 10 Jun 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Anujk305
Anujk305 human Metapneumovirus \(hmpv\) - Testing Management System
CPEs cpe:2.3:a:anujk305:human_metapneumovirus_\(hmpv\)_-_testing_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Anujk305
Anujk305 human Metapneumovirus \(hmpv\) - Testing Management System

Mon, 09 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 00:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /registered-user-testing.php. The manipulation of the argument testtype leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Title PHPGurukul Human Metapneumovirus Testing Management System registered-user-testing.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-06-09T14:43:36.756Z

Reserved: 2025-06-05T04:37:27.484Z

Link: CVE-2025-5707

cve-icon Vulnrichment

Updated: 2025-06-09T14:43:27.211Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-06T01:15:25.440

Modified: 2025-06-10T15:00:28.237

Link: CVE-2025-5707

cve-icon Redhat

No data.