Description
A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0. This vulnerability affects unknown code of the file /edit-course.php. Such manipulation of the argument Course Short Name leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Problem types
Product status
Timeline
| 2026-03-01: | Advisory disclosed |
| 2026-03-01: | VulDB entry created |
| 2026-03-01: | VulDB entry last update |
Credits
AS-AbdulSamad (VulDB User)
References
vuldb.com/?id.348297 (VDB-348297 | PHPGurukul Student Record Management System edit-course.php cross site scripting)
vuldb.com/?ctiid.348297 (VDB-348297 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.763323 (Submit #763323 | PHPGurukul Student Record Management System 1.0 Stored XSS in [/edit-course.php] endpoint on [Course Short Name])
github.com/AS-AbdulSamad/CVEs/issues/2
phpgurukul.com/