PHPGurukul Complaint Management System complaint-search.php cross site scripting

CVE Details

Basic Information

Title PHPGurukul Complaint Management System complaint-search.php cross site scripting
Type cve
Published 2025-07-18T19:02:06.832Z
Modified 2025-07-18T19:02:06.832Z

Product Information

Vendor PHPGurukul
Product Complaint Management System
Version 2.0

CVSS Information

Base Score 5.1 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

AI Analysis

AI Description A medium severity cross-site scripting (XSS) vulnerability in PHPGurukul Complaint Management System 2.0 allows remote attackers to inject scripts via the Search argument in complaint-search.php. This could lead to session hijacking or unauthorized actions. It’s important to patch this issue to prevent potential exploitation.
AI Severity Medium
AI Vendor PHPGurukul
AI Product Complaint Management System
AI Version 2.0

Affected Products

  • PHPGurukul Complaint Management System 2.0

Additional Information

CWE List CWE-79, CWE-94
Source VulDB

Description

A vulnerability was found in PHPGurukul Complaint Management System 2.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/complaint-search.php. The manipulation of the argument Search leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.