CVE-2025-70892

Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly validate user-supplied input in the username parameter of the add-users.php endpoint.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpgurukul:cyber_cafe_management_system:1.0:*:*:*:*:*:*:*

History

17 Jun 2026, 10:03

Type Values Removed Values Added
Summary
  • (es) Phpgurukul Cyber Cafe Management System v1.0 contiene una vulnerabilidad de inyección SQL en el módulo de gestión de usuarios. La aplicación no valida correctamente la entrada proporcionada por el usuario en el parámetro username del endpoint add-users.PHP.

22 Jan 2026, 16:00

Type Values Removed Values Added
First Time Phpgurukul cyber Cafe Management System
Phpgurukul
CPE cpe:2.3:a:phpgurukul:cyber_cafe_management_system:1.0:*:*:*:*:*:*:*
References () https://github.com/efekaanakkar/Cyber-Cafe-Management-System-CVEs/tree/main/CVE-2025-70892 - () https://github.com/efekaanakkar/Cyber-Cafe-Management-System-CVEs/tree/main/CVE-2025-70892 - Exploit, Mitigation, Third Party Advisory
References () https://phpgurukul.com/cyber-cafe-management-system-using-php-mysql/ - () https://phpgurukul.com/cyber-cafe-management-system-using-php-mysql/ - Product

15 Jan 2026, 22:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-89

15 Jan 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 21:16

Updated : 2026-06-17 10:03


NVD link : CVE-2025-70892

Mitre link : CVE-2025-70892

CVE.ORG link : CVE-2025-70892


JSON object : View

Products Affected

phpgurukul

  • cyber_cafe_management_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')