CVE-2025-70893

A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1.0 within the adminprofile.php endpoint. The application fails to properly sanitize user-supplied input provided via the adminname parameter, allowing authenticated attackers to inject arbitrary SQL expressions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpgurukul:cyber_cafe_management_system:1.0:*:*:*:*:*:*:*

History

17 Jun 2026, 10:03

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de inyección SQL ciega basada en tiempo existe en PHPGurukul Cyber Cafe Management System v1.0 dentro del endpoint adminprofile.php. La aplicación no logra sanear correctamente la entrada proporcionada por el usuario a través del parámetro adminname, permitiendo a atacantes autenticados inyectar expresiones SQL arbitrarias.

22 Jan 2026, 16:00

Type Values Removed Values Added
CPE cpe:2.3:a:phpgurukul:cyber_cafe_management_system:1.0:*:*:*:*:*:*:*
References () https://github.com/efekaanakkar/Cyber-Cafe-Management-System-CVEs/tree/main/CVE-2025-70893 - () https://github.com/efekaanakkar/Cyber-Cafe-Management-System-CVEs/tree/main/CVE-2025-70893 - Exploit, Third Party Advisory
References () https://phpgurukul.com/cyber-cafe-management-system-using-php-mysql/ - () https://phpgurukul.com/cyber-cafe-management-system-using-php-mysql/ - Product
First Time Phpgurukul cyber Cafe Management System
Phpgurukul

15 Jan 2026, 22:16

Type Values Removed Values Added
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

15 Jan 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 21:16

Updated : 2026-06-17 10:03


NVD link : CVE-2025-70893

Mitre link : CVE-2025-70893

CVE.ORG link : CVE-2025-70893


JSON object : View

Products Affected

phpgurukul

  • cyber_cafe_management_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')