cbcvebase.

Phpgurukul Beauty Parlour Management System vulnerabilities

28 known vulnerabilities affecting phpgurukul/beauty_parlour_management_system.

Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL22HIGH2MEDIUM4

Vulnerabilities

Page 2 of 2
CVE-2025-10402P3CRITICALCVSS 9.8v1.12025-09-14
CVE-2025-10402 [CRITICAL] CWE-74 CVE-2025-10402: A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /admin/readenq.php. Executing manipulation of the argument delid can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
nvd
CVE-2024-51065P3CRITICALCVSS 9.8v1.12024-10-31
CVE-2024-51065 [CRITICAL] CWE-89 CVE-2024-51065: Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php v Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.
nvd
CVE-2024-53480P3CRITICALCVSS 9.8v1.12024-12-10
CVE-2024-53480 [CRITICAL] CWE-89 CVE-2024-53480: Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter.
nvd
CVE-2024-51066P3HIGHCVSS 7.5v1.12024-10-31
CVE-2024-51066 [HIGH] CWE-639 CVE-2024-51066: An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's B An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Management System v1.1 allows unauthorized access to the Personally Identifiable Information (PII) of other customers.
nvd
CVE-2021-27545P3MEDIUMCVSS 6.5v1.02021-04-15
CVE-2021-27545 [MEDIUM] CWE-89 CVE-2021-27545: SQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1. SQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to obtain sensitive database information by injecting SQL commands into the "sername" parameter.
nvd
CVE-2024-53481P4MEDIUMCVSS 6.1v1.12024-12-10
CVE-2024-53481 [MEDIUM] CWE-79 CVE-2024-53481: A Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Managemen A Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "Firstname" and "Last name" parameters.
nvd
CVE-2024-37798P4MEDIUMCVSS 5.9v1.02024-06-17
CVE-2024-37798 [MEDIUM] CWE-79 CVE-2024-37798: Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Beauty Parlour Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input field.
nvd
CVE-2021-27544P4MEDIUMCVSS 4.8v1.02021-04-15
CVE-2021-27544 [MEDIUM] CWE-79 CVE-2021-27544: Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Manageme Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "sername" parameter.
nvd