CVE-2025-51414: Code Injection
Published Apr 13, 2026
·Updated
In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile picture upload functionality on the /my-profile.php page.
Affected Software
1 affected component
Phpgurukul PHPGurukul Online Course Registration=3.1
Event History
Apr 13, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Jan 14, 58258
Event
via NVD·02:39 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-51414?
CVE-2025-51414 has been classified as a critical severity vulnerability due to its potential for arbitrary file uploads.
2
How do I fix CVE-2025-51414?
To fix CVE-2025-51414, restrict the file types allowed for upload and implement file validation checks on the /my-profile.php page.
3
What systems are affected by CVE-2025-51414?
CVE-2025-51414 affects Phpgurukul Online Course Registration version 3.1.
4
What type of vulnerability is CVE-2025-51414?
CVE-2025-51414 is classified as an arbitrary file upload vulnerability.
5
Can CVE-2025-51414 lead to remote code execution?
Yes, CVE-2025-51414 can lead to remote code execution if attackers successfully upload a malicious file.