CVE-2026-3403
- EPSS 0.03%
- Veröffentlicht 02.03.2026 01:02:09
- Zuletzt bearbeitet 03.03.2026 19:47:11
A vulnerability was detected in PHPGurukul Student Record Management System 1.0. This issue affects some unknown processing of the file /edit-subject.php. Performing a manipulation of the argument Subject 1 results in cross site scripting. The attack...
CVE-2026-3402
- EPSS 0.03%
- Veröffentlicht 02.03.2026 00:32:09
- Zuletzt bearbeitet 03.03.2026 19:47:22
A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0. This vulnerability affects unknown code of the file /edit-course.php. Such manipulation of the argument Course Short Name leads to cross site scripti...
CVE-2025-63955
- EPSS 0.03%
- Veröffentlicht 18.11.2025 00:00:00
- Zuletzt bearbeitet 20.11.2025 17:27:58
A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request. This leads to the unauthorize...
CVE-2024-44640
- EPSS 0.04%
- Veröffentlicht 14.11.2025 16:15:48
- Zuletzt bearbeitet 17.11.2025 18:21:47
PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the course-short, course-full, and cdate parameters in add-course.php.
CVE-2024-44639
- EPSS 0.04%
- Veröffentlicht 14.11.2025 16:15:48
- Zuletzt bearbeitet 17.11.2025 18:21:54
PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the sub1, sub2, sub3, sub4, and course-short parameters in add-subject.php.
CVE-2024-55016
- EPSS 0.04%
- Veröffentlicht 14.11.2025 00:00:00
- Zuletzt bearbeitet 17.11.2025 18:20:54
PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php.
CVE-2024-44636
- EPSS 0.05%
- Veröffentlicht 14.11.2025 00:00:00
- Zuletzt bearbeitet 17.11.2025 18:22:00
PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid parameters in /admin-profile.php.
CVE-2024-44630
- EPSS 0.04%
- Veröffentlicht 14.11.2025 00:00:00
- Zuletzt bearbeitet 17.11.2025 17:40:28
Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These include: c-full, fname, mname,lname, gname, ocp, nation, mobno, email, board1, roll1, pyear1, board2, roll2, pyear2, sub1,marks1, sub2...
CVE-2024-44635
- EPSS 0.05%
- Veröffentlicht 14.11.2025 00:00:00
- Zuletzt bearbeitet 17.11.2025 18:22:07
PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and aemailid parameters in /admin-profile.php.
CVE-2024-44633
- EPSS 0.04%
- Veröffentlicht 14.11.2025 00:00:00
- Zuletzt bearbeitet 17.11.2025 17:35:46
PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword parameter in change-password.php.