PT-2025-38709 · Phpgurukul · Phpgurukul Car Rental Project

Tddgns

·

Published

2025-09-22

·

Updated

2025-09-22

·

CVE-2025-10794

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHPGurukul Car Rental Project version 3.0
Description A flaw exists in the PHPGurukul Car Rental Project version 3.0, specifically within the /carrental/search.php file. Manipulation of the autofocus argument can lead to cross site scripting (XSS). This attack can be launched remotely. The exploit has been published.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-10794

Affected Products

Phpgurukul Car Rental Project