Skip to main content

Vendor archive

phpgurukul CVEs

Beta · best-effort

1,062 CVEs tagged to vendor phpgurukul107 Critical, 104 High, 696 Medium, 155 Low, 0 Unrated.

CVE-2024-30990

Published Apr 17, 2024

SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "searchdata"…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-30989

Published Apr 17, 2024

Cross Site Scripting vulnerability in /edit-client-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code via the "cna…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30988

Published Apr 17, 2024

Cross Site Scripting vulnerability in /search-invoices.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30987

Published Apr 17, 2024

Cross Site Scripting vulnerability in /bwdates-reports-ds.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain se…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30986

Published Apr 17, 2024

Cross Site Scripting vulnerability in /edit-services-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and via "p…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30985

Published Apr 17, 2024

SQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "todate"…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-30982

Published Apr 17, 2024

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter in the /view-use…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-30983

Published Apr 17, 2024

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the compname parameter in /edit-com…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-30981

Published Apr 17, 2024

SQL Injection vulnerability in /edit-computer-detail.php in phpgurukul Cyber Cafe Management System Using PHP & MySQL v1.0 allows attackers to run arbitrary SQL commands via editi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-30980

Published Apr 17, 2024

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the Computer Location parameter in…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-30979

Published Apr 17, 2024

Cross Site Scripting vulnerability in Cyber Cafe Management System 1.0 allows a remote attacker to execute arbitrary code via the compname parameter in edit-computer-details.php.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32256

Published Apr 16, 2024

Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via /tms/admin/change-image.php. When updating a current package, there…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-32254

Published Apr 16, 2024

Phpgurukul Tourism Management System v2.0 is vulnerable to Unrestricted Upload of File with Dangerous Type via tms/admin/create-package.php. When creating a new package, there is…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3771

Published Apr 15, 2024

A vulnerability was found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this issue is some unknown functionality of the file /edit-subject.php.…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3770

Published Apr 15, 2024

A vulnerability has been found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manage-…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3769

Published Apr 15, 2024

A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an unknown function of the file /login.php. The manipulation of…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3768

Published Apr 15, 2024

A vulnerability, which was classified as critical, has been found in PHPGurukul/itsourcecode News Portal 4.1. This issue affects some unknown processing of the file search.php. Th…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3767

Published Apr 15, 2024

A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code of the file /admin/edit-post.php. The manipulation of the a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3691

Published Apr 12, 2024

A vulnerability, which was classified as critical, has been found in PHPGurukul Small CRM 3.0. Affected by this issue is some unknown functionality of the component Registration P…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3690

Published Apr 12, 2024

A vulnerability classified as critical was found in PHPGurukul Small CRM 3.0. Affected by this vulnerability is an unknown functionality of the component Change Password Handler.…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30998

Published Apr 3, 2024

SQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via the email param…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 801-825 of 1,062 CVEsPage 33 of 43