CVE-2025-15390

A security flaw has been discovered in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /admin/edit-user.php. The manipulation results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpgurukul:small_crm:*:*:*:*:*:*:*:*

History

13 Jan 2026, 22:29

Type Values Removed Values Added
First Time Phpgurukul small Crm
Phpgurukul
CPE cpe:2.3:a:phpgurukul:small_crm:*:*:*:*:*:*:*:*
References () https://github.com/rsecroot/Small-Customer-Relationship-Management-CRM-in-PHP/blob/main/Broken%20Access%20Control.md - () https://github.com/rsecroot/Small-Customer-Relationship-Management-CRM-in-PHP/blob/main/Broken%20Access%20Control.md - Exploit, Third Party Advisory
References () https://phpgurukul.com/ - () https://phpgurukul.com/ - Product
References () https://vuldb.com/?ctiid.339151 - () https://vuldb.com/?ctiid.339151 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.339151 - () https://vuldb.com/?id.339151 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.727430 - () https://vuldb.com/?submit.727430 - Third Party Advisory, VDB Entry

31 Dec 2025, 17:15

Type Values Removed Values Added
References () https://github.com/rsecroot/Small-Customer-Relationship-Management-CRM-in-PHP/blob/main/Broken%20Access%20Control.md - () https://github.com/rsecroot/Small-Customer-Relationship-Management-CRM-in-PHP/blob/main/Broken%20Access%20Control.md -

31 Dec 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-31 16:15

Updated : 2026-01-13 22:29


NVD link : CVE-2025-15390

Mitre link : CVE-2025-15390

CVE.ORG link : CVE-2025-15390


JSON object : View

Products Affected

phpgurukul

  • small_crm
CWE
CWE-862

Missing Authorization

CWE-863

Incorrect Authorization