Search Results (31 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-45010 1 Phpgurukul 1 Park Ticketing Management System 2025-05-09 5.3 Medium
A HTML Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the fromdate and todate POST request parameters.
CVE-2025-45011 1 Phpgurukul 1 Park Ticketing Management System 2025-05-09 5.3 Medium
A HTML Injection vulnerability was discovered in the foreigner-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the searchdata POST request parameter.
CVE-2025-45015 1 Phpgurukul 1 Park Ticketing Management System 2025-05-09 6.1 Medium
A Cross-Site Scripting (XSS) vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. The vulnerability allows remote attackers to inject arbitrary JavaScript code via the fromdate and todate parameters.
CVE-2025-45017 1 Phpgurukul 1 Park Ticketing Management System 2025-05-09 9.8 Critical
A SQL injection vulnerability was discovered in edit-ticket.php of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the tprice POST request parameter.
CVE-2025-45018 1 Phpgurukul 1 Park Ticketing Management System 2025-05-09 9.8 Critical
A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the todate parameter.
CVE-2025-45019 1 Phpgurukul 1 Park Ticketing Management System 2025-05-09 9.8 Critical
A SQL injection vulnerability was discovered in /add-foreigners-ticket.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the cprice POST request parameter.
CVE-2025-45021 1 Phpgurukul 1 Directory Management System 2025-05-09 5.3 Medium
A SQL Injection vulnerability was identified in the admin/edit-directory.php file of the PHPGurukul Directory Management System v2.0. Attackers can exploit this vulnerability via the email parameter in a POST request to execute arbitrary SQL commands.
CVE-2022-42206 1 Phpgurukul 1 Hospital Management System 2025-05-08 5.4 Medium
PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via doctor/view-patient.php, admin/view-patient.php, and view-medhistory.php.
CVE-2022-42205 1 Phpgurukul 1 Hospital Management System 2025-05-08 5.4 Medium
PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via add-patient.php.
CVE-2025-1966 1 Phpgurukul 1 Pre-school Enrollment System 2025-04-02 7.3 High
A vulnerability classified as critical was found in PHPGurukul Pre-School Enrollment System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2023-37771 1 Phpgurukul 1 Art Gallery Management System 2024-11-21 9.8 Critical
Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php.