PT-2025-30266 · Unknown · Phpgurukul Online Banquet Booking System

Longlagon

·

Published

2025-07-21

·

Updated

2025-07-21

·

CVE-2025-7925

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHPGurukul Online Banquet Booking System version 1.0
Description A cross site scripting issue exists due to the manipulation of the user login/userpassword argument in the /admin/login.php file. The attack can be launched remotely. The exploit has been publicly disclosed.
Recommendations As a temporary workaround, consider restricting access to the /admin/login.php file until a fix is available. Sanitize the user login and userpassword parameters to prevent the injection of malicious scripts.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-7925

Affected Products

Phpgurukul Online Banquet Booking System