CVE-2025-70893: Phpgurukul Cyber Cafe Management System

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A time-based blind SQL Injection vulnerability exists in PHPGurukul Cyber Cafe Management System v1.0 within the adminprofile.php endpoint. The application fails to properly sanitize user-supplied input provided via the adminname parameter, allowing authenticated attackers to inject arbitrary SQL expressions.

Affected products

  • Phpgurukul Cyber Cafe Management System: version 1.0 only

Published 2026-01-15. Last modified 2026-06-17.