Vulnerability record · CVE-2025-70892 · published 15 January 2026
CVE-2025-70892: Phpgurukul cyber cafe management system sql injection vulnerability
Phpgurukul · Cyber Cafe Management System
Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly validate user-supplied input in the username parameter of the add-users.php endpoint.
Description
Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The application fails to properly validate user-supplied input in the username parameter of the add-users.php endpoint.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/efekaanakkar/Cyber-Cafe-Management-System-CVEs/tree/main/CVE-2025-70892 | ExploitMitigationThird Party Advisory |
| https://phpgurukul.com/cyber-cafe-management-system-using-php-mysql/ | Product |
Track CVE-2025-70892 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-70892), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.