Vulnerabilities (CVE)

Filtered by vendor Phpgurukul Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-0286 1 Phpgurukul 1 Hospital Management System 2024-01-11 N/A 6.1 MEDIUM
A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file index.php#contact_us of the component Contact Form. The manipulation of the argument Name/Email/Message leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249843.
CVE-2023-7173 1 Phpgurukul 1 Hospital Management System 2024-01-08 N/A 5.4 MEDIUM
A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file registration.php. The manipulation of the argument First Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249357 was assigned to this vulnerability.
CVE-2023-7050 1 Phpgurukul 1 Online Notes Sharing System 2023-12-29 N/A 5.4 MEDIUM
A vulnerability has been found in PHPGurukul Online Notes Sharing System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file user/profile.php. The manipulation of the argument name/email leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248737 was assigned to this vulnerability.
CVE-2023-0563 1 Phpgurukul 1 Bank Locker Management System 2023-12-28 N/A 4.8 MEDIUM
A vulnerability classified as problematic has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file add-locker-form.php of the component Assign Locker. The manipulation of the argument ahname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-219717 was assigned to this vulnerability.
CVE-2023-36942 1 Phpgurukul 1 Online Fire Reporting System 2023-12-28 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the website title field.
CVE-2023-7055 1 Phpgurukul 1 Online Notes Sharing System 2023-12-28 N/A 5.4 MEDIUM
A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing System 1.0. Affected is an unknown function of the file /user/profile.php of the component Contact Information Handler. The manipulation of the argument mobilenumber leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-248742 is the identifier assigned to this vulnerability.
CVE-2023-7054 1 Phpgurukul 1 Online Notes Sharing System 2023-12-28 N/A 5.4 MEDIUM
A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /user/add-notes.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248741 was assigned to this vulnerability.
CVE-2023-7052 1 Phpgurukul 1 Online Notes Sharing System 2023-12-28 N/A 4.3 MEDIUM
A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been classified as problematic. This affects an unknown part of the file /user/profile.php. The manipulation of the argument name leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248739.
CVE-2023-7051 1 Phpgurukul 1 Online Notes Sharing System 2023-12-28 N/A 4.3 MEDIUM
A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /user/manage-notes.php of the component Notes Handler. The manipulation of the argument delid leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-248738 is the identifier assigned to this vulnerability.
CVE-2023-36375 1 Phpgurukul 1 Hostel Management System 2023-12-22 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the Guardian name, Guardian relation, complimentary address, city, permanent address, and city parameters in the Book Hostel & Room Details page.
CVE-2023-36939 1 Phpgurukul 1 Hostel Management System 2023-12-22 N/A 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the search booking field.
CVE-2022-30930 1 Phpgurukul 1 Tourism Management System 2023-12-22 4.3 MEDIUM 4.3 MEDIUM
Tourism Management System Version: V 3.2 is affected by: Cross Site Request Forgery (CSRF).
CVE-2023-36376 1 Phpgurukul 1 Hostel Management System 2023-12-22 N/A 4.8 MEDIUM
Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the add course section.
CVE-2023-1909 1 Phpgurukul 1 Bp Monitoring Management System 2023-12-21 N/A 6.5 MEDIUM
A vulnerability, which was classified as critical, was found in PHPGurukul BP Monitoring Management System 1.0. Affected is an unknown function of the file profile.php of the component User Profile Update Handler. The manipulation of the argument name/mobno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225318 is the identifier assigned to this vulnerability.
CVE-2023-1948 1 Phpgurukul 1 Bp Monitoring Management System 2023-12-21 N/A 6.1 MEDIUM
A vulnerability, which was classified as problematic, has been found in PHPGurukul BP Monitoring Management System 1.0. This issue affects some unknown processing of the file add-family-member.php of the component Add New Family Member Handler. The manipulation of the argument Member Name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225335.
CVE-2023-26958 1 Phpgurukul 1 Park Ticketing Management System 2023-12-21 N/A 4.8 MEDIUM
Phpgurukul Park Ticketing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Admin Name parameter.
CVE-2023-36940 1 Phpgurukul 1 Online Fire Reporting System 2023-12-21 N/A 4.8 MEDIUM
Cross Site Scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL v.1.2 allows attackers to execute arbitrary code via a crafted payload injected into the search field.
CVE-2023-36936 1 Phpgurukul 1 Online Security Guards Hiring System 2023-12-21 N/A 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in PHPGurukul Online Security Guards Hiring System using PHP and MySQL 1.0 allows attackers to execute arbitrary code via a crafted payload to the search booking box.
CVE-2023-33580 1 Phpgurukul 1 Student Study Center Management System 2023-12-21 N/A 4.8 MEDIUM
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" field on Admin Profile page.
CVE-2023-36941 1 Phpgurukul 1 Online Fire Reporting System 2023-12-21 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the team name, leader, and member fields.
CVE-2023-31934 1 Phpgurukul 1 Rail Pass Management System 2023-12-20 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the adminname parameter of admin-profile.php.
CVE-2023-31935 1 Phpgurukul 1 Rail Pass Management System 2023-12-20 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the emial parameter of admin-profile.php.
CVE-2023-23157 1 Phpgurukul 1 Art Gallery Management System 2023-12-20 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fullname parameter on the enquiry page.
CVE-2023-37743 1 Phpgurukul 1 Teacher Subject Allocation System 2023-12-20 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Teacher Subject Allocation System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search text box.
CVE-2023-23158 1 Phpgurukul 1 Art Gallery Management System 2023-12-20 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the message parameter on the enquiry page.
CVE-2023-23161 1 Phpgurukul 1 Art Gallery Management System 2023-12-20 N/A 6.1 MEDIUM
A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the artname parameter under ART TYPE option in the navigation bar.
CVE-2023-6649 1 Phpgurukul 1 Teacher Subject Allocation Management System 2023-12-13 N/A 6.1 MEDIUM
A vulnerability has been found in PHPGurukul Teacher Subject Allocation Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file index.php. The manipulation of the argument searchdata with the input <script>alert(5)</script> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-247342 is the identifier assigned to this vulnerability.
CVE-2023-6653 1 Phpgurukul 1 Teacher Subject Allocation Management System 2023-12-13 N/A 4.3 MEDIUM
A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/subject.php of the component Create a new Subject. The manipulation of the argument cid leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247346 is the identifier assigned to this vulnerability.
CVE-2023-6474 1 Phpgurukul 1 Nipah Virus Testing Management System 2023-12-08 N/A 6.5 MEDIUM
A vulnerability has been found in PHPGurukul Nipah Virus Testing Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file manage-phlebotomist.php. The manipulation of the argument pid leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-246640.
CVE-2023-6465 1 Phpgurukul 1 Nipah Virus Testing Management System 2023-12-06 N/A 6.1 MEDIUM
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been classified as problematic. This affects an unknown part of the file registered-user-testing.php. The manipulation of the argument regmobilenumber leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246615.
CVE-2023-6442 1 Phpgurukul 1 Nipah Virus Testing Management System 2023-12-06 N/A 5.4 MEDIUM
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file add-phlebotomist.php. The manipulation of the argument empid/fullname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-246445 was assigned to this vulnerability.
CVE-2023-6297 1 Phpgurukul 1 Nipah Virus Testing Management System 2023-11-30 N/A 6.1 MEDIUM
A vulnerability classified as problematic has been found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of the file patient-search-report.php of the component Search Report Page. The manipulation of the argument Search By Patient Name with the input <script>alert(document.cookie)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246123.
CVE-2023-47446 1 Phpgurukul 1 Pre-school Enrollment System 2023-11-20 N/A 5.4 MEDIUM
Pre-School Enrollment version 1.0 is vulnerable to Cross Site Scripting (XSS) on the profile.php page via fullname parameter.
CVE-2023-46025 1 Phpgurukul 1 Teacher Subject Allocation Management System 2023-11-17 N/A 4.9 MEDIUM
SQL Injection vulnerability in teacher-info.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to obtain sensitive information via the 'editid' parameter.
CVE-2023-46026 1 Phpgurukul 1 Teacher Subject Allocation Management System 2023-11-17 N/A 4.8 MEDIUM
Cross Site Scripting (XSS) vulnerability in profile.php in phpgurukul Teacher Subject Allocation Management System 1.0 allows attackers to run arbitrary code via the 'adminname' and 'email' parameters.
CVE-2023-6075 1 Phpgurukul 1 Restaurant Table Booking System 2023-11-16 N/A 6.1 MEDIUM
A vulnerability classified as problematic has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file index.php of the component Reservation Request Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-244944.
CVE-2020-5308 1 Phpgurukul 1 Dairy Farm Shop Management System 2023-11-14 4.3 MEDIUM 6.1 MEDIUM
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to XSS, as demonstrated by the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName parameter in add-product.php.
CVE-2021-27545 1 Phpgurukul 1 Beauty Parlour Management System 2023-11-14 4.0 MEDIUM 6.5 MEDIUM
SQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to obtain sensitive database information by injecting SQL commands into the "sername" parameter.
CVE-2021-27544 1 Phpgurukul 1 Beauty Parlour Management System 2023-11-14 3.5 LOW 4.8 MEDIUM
Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "sername" parameter.
CVE-2022-43369 1 Phpgurukul 1 Auto\/taxi Stand Management System 2023-11-14 N/A 6.1 MEDIUM
AutoTaxi Stand Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component search.php.
CVE-2022-29004 1 Phpgurukul 1 E-diary Management System 2023-11-14 4.3 MEDIUM 6.1 MEDIUM
Diary Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name parameter in search-result.php.
CVE-2022-47102 1 Phpgurukul 1 Student Study Center Management System 2023-11-14 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in Student Study Center Management System V 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
CVE-2023-37688 1 Phpgurukul 1 Maid Hiring Management System 2023-11-14 N/A 4.8 MEDIUM
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Admin page.
CVE-2023-37746 1 Phpgurukul 1 Maid Hiring Management System 2023-11-14 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Maid Hiring Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter of the /admin/contactus.php component.
CVE-2023-37745 1 Phpgurukul 1 Maid Hiring Management System 2023-11-14 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Maid Hiring Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Description of the /admin/aboutus.php component.
CVE-2023-37744 1 Phpgurukul 1 Maid Hiring Management System 2023-11-14 N/A 6.1 MEDIUM
Maid Hiring Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-booking-request.php.
CVE-2023-37690 1 Phpgurukul 1 Maid Hiring Management System 2023-11-14 N/A 4.8 MEDIUM
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Search Maid page.
CVE-2023-37689 1 Phpgurukul 1 Maid Hiring Management System 2023-11-14 N/A 4.8 MEDIUM
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Booking Request page.
CVE-2022-40470 1 Phpgurukul 1 Blood Donor Management System 2023-11-14 N/A 4.8 MEDIUM
Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature.
CVE-2023-37686 1 Phpgurukul 1 Online Nurse Hiring System 2023-11-14 N/A 4.8 MEDIUM
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Nurse Page in the Admin portal.