Severity
4.8MEDIUM
EPSS
0.0%
top 88.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 2

Description

A vulnerability was detected in PHPGurukul Student Record Management System 1.0. This issue affects some unknown processing of the file /edit-subject.php. Performing a manipulation of the argument Subject 1 results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-j9fg-w4w9-vgr8: A vulnerability was detected in PHPGurukul Student Record Management System 12026-03-02
CVEList
PHPGurukul Student Record Management System edit-subject.php cross site scripting2026-03-02
CVE-2026-3403 (MEDIUM CVSS 4.8) | A vulnerability was detected in PHP | cvebase.io