CVE-2025-45947
Critical · CVSS 9.8phpgurukul Online Banquet Booking System — Code Injection (CWE-94) - Arbitrary Code Execution via Change Password component
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-94
Description
An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php file of the My Account - Change Password component
Search profile — drives PoC discovery
Symbols /obbs/change-password.phpchange-password.phpMy AccountChange Passwordobbs
Keywords CVE-2025-45947phpgurukulOnline Banquet Booking Systemchange-password.phparbitrary code executionobbscode injectionV1.2
Versions: V1.2
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z