CVE-2025-28016
- EPSS 0.04%
- Veröffentlicht 30.09.2025 15:15:48
- Zuletzt bearbeitet 07.10.2025 13:42:23
A Reflected Cross-Site Scripting (XSS) vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and User Management System V3.3. This vulnerability allows remote attackers to execute arbitrary JavaScript cod...
CVE-2025-10624
- EPSS 0.03%
- Veröffentlicht 17.09.2025 22:32:11
- Zuletzt bearbeitet 19.09.2025 20:39:32
A security flaw has been discovered in PHPGurukul User Management System 1.0. This affects an unknown function of the file /login.php. Performing manipulation of the argument emailid results in sql injection. The attack can be initiated remotely. The...
CVE-2025-10098
- EPSS 0.03%
- Veröffentlicht 08.09.2025 17:02:07
- Zuletzt bearbeitet 12.09.2025 20:52:00
A security flaw has been discovered in PHPGurukul User Management System 1.0. Affected is an unknown function of the file /admin/edit-user-profile.php. The manipulation of the argument uid results in sql injection. The attack may be performed from re...
CVE-2025-9756
- EPSS 0.03%
- Veröffentlicht 01.09.2025 02:02:07
- Zuletzt bearbeitet 08.09.2025 14:02:39
A vulnerability was found in PHPGurukul User Management System 1.0. This impacts an unknown function of the file /admin/change-emailid.php. The manipulation of the argument uid results in sql injection. The attack can be executed remotely. The exploi...
CVE-2025-9302
- EPSS 0.03%
- Veröffentlicht 21.08.2025 14:02:06
- Zuletzt bearbeitet 22.08.2025 21:16:52
A vulnerability was identified in PHPGurukul User Management System 1.0. This vulnerability affects unknown code of the file /signup.php. Such manipulation of the argument emailid leads to sql injection. The attack can be executed remotely. The explo...
CVE-2025-8158
- EPSS 0.03%
- Veröffentlicht 25.07.2025 14:15:36
- Zuletzt bearbeitet 29.07.2025 17:18:42
A vulnerability was found in PHPGurukul Login and User Management System 3.3. It has been declared as critical. This vulnerability affects unknown code of the file /admin/yesterday-reg-users.php. The manipulation of the argument ID leads to sql injec...
CVE-2024-50991
- EPSS 0.13%
- Veröffentlicht 11.11.2024 15:15:06
- Zuletzt bearbeitet 04.04.2025 20:00:24
A Cross Site Scripting (XSS) vulnerability was found in /ums-sp/admin/registered-users.php in PHPGurukul User Management System v1.0, which allows remote attackers to execute arbitrary code via the "fname" POST request parameter