PT-2025-18274 · Unknown · Phpgurukul Park Ticketing Management System

Published

2025-04-30

·

Updated

2025-04-30

·

CVE-2025-45015

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHPGurukul Park Ticketing Management System version 2.0
Description A Cross-Site Scripting (XSS) issue was discovered in the foreigner-bwdates-reports-details.php file. This issue allows remote attackers to inject arbitrary JavaScript code via the fromdate and todate parameters.
Recommendations For PHPGurukul Park Ticketing Management System version 2.0, consider disabling the foreigner-bwdates-reports-details.php file or restricting access to it until a patch is available. Additionally, avoid using the fromdate and todate parameters in the affected file until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-45015

Affected Products

Phpgurukul Park Ticketing Management System