Filtered by vendor Phpgurukul
Subscribe
Total
862 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2025-10098 | 1 Phpgurukul | 1 User Management System | 2025-09-12 | 6.5 MEDIUM | 6.3 MEDIUM |
A security flaw has been discovered in PHPGurukul User Management System 1.0. Affected is an unknown function of the file /admin/edit-user-profile.php. The manipulation of the argument uid results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be exploited. | |||||
CVE-2025-40687 | 1 Phpgurukul | 1 Online Fire Reporting System | 2025-09-12 | N/A | 9.8 CRITICAL |
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'mobilenumber', 'teamleadname' and 'teammember' parameters in the endpoint '/ofrs/admin/add-team.php'. | |||||
CVE-2025-40689 | 1 Phpgurukul | 1 Online Fire Reporting System | 2025-09-12 | N/A | 9.8 CRITICAL |
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'remark', 'status' and 'requestid' parameters in the endpoint '/ofrs/admin/request-details.php'. | |||||
CVE-2025-40690 | 1 Phpgurukul | 1 Online Fire Reporting System | 2025-09-12 | N/A | 9.8 CRITICAL |
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'teamid' parameter in the endpoint '/ofrs/admin/edit-team.php'. | |||||
CVE-2025-40691 | 1 Phpgurukul | 1 Online Fire Reporting System | 2025-09-12 | N/A | 9.8 CRITICAL |
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'todate' parameter in the endpoint '/ofrs/admin/bwdates-report-result.php'. | |||||
CVE-2025-40692 | 1 Phpgurukul | 1 Online Fire Reporting System | 2025-09-12 | N/A | 9.8 CRITICAL |
SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'requestid' parameter in the endpoint '/ofrs/details.php'. | |||||
CVE-2025-40693 | 1 Phpgurukul | 1 Online Fire Reporting System | 2025-09-12 | N/A | 5.4 MEDIUM |
Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a reflected and stored authenticated XSS due to the lack of propper validation of user inputs 'tname' parameter via GET and, 'teamleadname', 'teammember' and 'teamname' parameters via POST at the endpoint '/ofrs/admin/edit-team.php'. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal its cookie session details. | |||||
CVE-2025-40694 | 1 Phpgurukul | 1 Online Fire Reporting System | 2025-09-12 | N/A | 5.4 MEDIUM |
Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'fromdate' and 'todate' parameters via POST at the endpoint '/ofrs/admin/bwdates-report-result.php'. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal its cookie session details. | |||||
CVE-2025-40695 | 1 Phpgurukul | 1 Online Fire Reporting System | 2025-09-12 | N/A | 5.4 MEDIUM |
Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'remark', 'status' and 'takeaction' parameters via POST at the endpoint '/ofrs/admin/request-details.php'. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal its cookie session details. | |||||
CVE-2025-40696 | 1 Phpgurukul | 1 Online Fire Reporting System | 2025-09-12 | N/A | 5.4 MEDIUM |
Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated XSS due to the lack of propper validation of user inputs 'fullname', 'location' and 'message' parameters via POST at the endpoint '/ofrs/reporting.php'. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal its cookie session details. | |||||
CVE-2025-57576 | 1 Phpgurukul | 1 Online Shopping Portal | 2025-09-10 | N/A | 5.4 MEDIUM |
PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) in /admin/updateorder.php. | |||||
CVE-2025-10025 | 1 Phpgurukul | 1 Online Course Registration | 2025-09-10 | 7.5 HIGH | 7.3 HIGH |
A vulnerability has been found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file /admin/semester.php. The manipulation of the argument semester leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-10114 | 1 Phpgurukul | 1 Small Crm | 2025-09-10 | 7.5 HIGH | 7.3 HIGH |
A vulnerability was found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /profile.php. The manipulation of the argument Name results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. | |||||
CVE-2025-45805 | 1 Phpgurukul | 1 Doctor Appointment Management System | 2025-09-08 | N/A | 7.6 HIGH |
In phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their profile name. This payload is subsequently rendered without proper sanitization, when a user visits the website and selects the doctor to book an appointment. | |||||
CVE-2025-57146 | 1 Phpgurukul | 1 Complaint Management System | 2025-09-08 | N/A | 8.1 HIGH |
phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobileno parameter. | |||||
CVE-2025-57147 | 1 Phpgurukul | 1 Complaint Management System | 2025-09-08 | N/A | 7.5 HIGH |
A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2.0. The vulnerability is due to lack of input validation of multiple parameters including fullname, email, and contactno in user/registration.php. | |||||
CVE-2025-9932 | 1 Phpgurukul | 1 Beauty Parlour Management System | 2025-09-08 | 7.5 HIGH | 7.3 HIGH |
A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /admin/update-image.php. This manipulation of the argument lid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |||||
CVE-2025-9933 | 1 Phpgurukul | 1 Beauty Parlour Management System | 2025-09-08 | 7.5 HIGH | 7.3 HIGH |
A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file /admin/view-appointment.php. Such manipulation of the argument viewid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2025-9729 | 1 Phpgurukul | 1 Online Course Registration | 2025-09-08 | 7.5 HIGH | 7.3 HIGH |
A vulnerability was detected in PHPGurukul Online Course Registration 3.1. This vulnerability affects unknown code of the file /admin/student-registration.php. Performing manipulation of the argument studentname results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |||||
CVE-2025-9756 | 1 Phpgurukul | 1 User Management System | 2025-09-08 | 6.5 MEDIUM | 6.3 MEDIUM |
A vulnerability was found in PHPGurukul User Management System 1.0. This impacts an unknown function of the file /admin/change-emailid.php. The manipulation of the argument uid results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. |