PT-2025-37487 · Phpgurukul · Phpgurukul Student-Result-Management-System-Using-Php-V2.0

Published

2025-09-15

·

Updated

2025-09-15

·

CVE-2025-56710

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions PHPGurukul Student-Result-Management-System-Using-PHP-V2.0 version 2.0
Description A Cross-Site Request Forgery (CSRF) flaw exists in the Profile Page of the software. This allows an attacker to trick authenticated users into unintentionally modifying their account details. The attacker can submit unauthorized requests to the vulnerable endpoint: /create-class.php.
Recommendations As a mitigation, consider implementing CSRF protection mechanisms, such as synchronizer tokens, to validate requests.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-56710

Affected Products

Phpgurukul Student-Result-Management-System-Using-Php-V2.0