CVE-2025-4757
- EPSS 0.07%
- Veröffentlicht 16.05.2025 07:31:08
- Zuletzt bearbeitet 27.05.2025 19:49:21
A vulnerability was found in PHPGurukul Beauty Parlour Management System 1.1. It has been rated as critical. This issue affects some unknown processing of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. T...
CVE-2024-53481
- EPSS 0.12%
- Veröffentlicht 10.12.2024 20:15:21
- Zuletzt bearbeitet 15.04.2025 20:35:16
A Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "Firstname" and "Last name" parameters.
CVE-2024-53480
- EPSS 0.16%
- Veröffentlicht 10.12.2024 20:15:20
- Zuletzt bearbeitet 07.04.2025 15:17:50
Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter.
CVE-2024-51066
- EPSS 0.17%
- Veröffentlicht 31.10.2024 19:15:13
- Zuletzt bearbeitet 04.04.2025 14:35:51
An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Management System v1.1 allows unauthorized access to the Personally Identifiable Information (PII) of other customers.
CVE-2024-51065
- EPSS 0.13%
- Veröffentlicht 31.10.2024 19:15:13
- Zuletzt bearbeitet 31.03.2025 19:29:35
Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.
CVE-2024-37798
- EPSS 0.24%
- Veröffentlicht 17.06.2024 21:15:51
- Zuletzt bearbeitet 03.04.2025 00:48:05
Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Beauty Parlour Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input field.
CVE-2021-27544
- EPSS 0.35%
- Veröffentlicht 15.04.2021 12:15:13
- Zuletzt bearbeitet 21.11.2024 05:58:10
Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "sername" parameter.
CVE-2021-27545
- EPSS 1.16%
- Veröffentlicht 15.04.2021 12:15:13
- Zuletzt bearbeitet 21.11.2024 05:58:10
SQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to obtain sensitive database information by injecting SQL commands into the "sername" parameter.