CVE Details
Basic Information
| Title | PHPGurukul Restaurant Table Booking System add-subadmin.php cross site scripting |
|---|---|
| Type | cve |
| Published | 2025-06-10T17:00:10.161Z |
| Last Seen |
Product Information
| Vendor | PHPGurukul |
|---|---|
| Product | Restaurant Table Booking System |
| Version | 1.0 |
CVSS Information
| Base Score | 4.8 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A cross-site scripting vulnerability in the Restaurant Table Booking System allows attackers to inject malicious scripts via the fullname parameter in add-subadmin.php. This can lead to session hijacking or unauthorized actions. It’s remotely exploitable and affects version 1.0. |
|---|---|
| AI Severity | Medium |
| Vendor | PHPGurukul |
| Product | Restaurant Table Booking System |
| Affected Version | 1.0 |
Affected Products
- PHPGurukul Restaurant Table Booking System 1.0
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-79, CWE-94 |
| Bulletin Family |
References
Description
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.