CVE Details
Basic Information
| Title | PHPGurukul Apartment Visitors Management System HTTP POST Request admin-profile.php cross site scripting |
|---|---|
| Type | cve |
| Published | 2025-07-19T23:44:07.035Z |
| Modified | 2025-07-19T23:44:07.035Z |
Product Information
| Vendor | PHPGurukul |
|---|---|
| Product | Apartment Visitors Management System |
| Version | 1.0 |
CVSS Information
| Base Score | 5.1 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P |
AI Analysis
| AI Description | A cross-site scripting (XSS) vulnerability in PHPGurukul Apartment Visitors Management System 1.0 allows remote attackers to inject malicious scripts via the adminname argument in admin-profile.php. |
|---|---|
| AI Severity | Medium |
| AI Vendor | PHPGurukul |
| AI Product | Apartment Visitors Management System |
| AI Version | 1.0 |
Affected Products
- PHPGurukul Apartment Visitors Management System 1.0
Additional Information
| CWE List | CWE-79, CWE-94 |
|---|---|
| Source | VulDB |
Description
A vulnerability classified as problematic has been found in PHPGurukul Apartment Visitors Management System 1.0. This affects an unknown part of the file /admin-profile.php of the component HTTP POST Request Handler. The manipulation of the argument adminname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.