Phpgurukul Beauty Parlour Management System vulnerabilities
28 known vulnerabilities affecting phpgurukul/beauty_parlour_management_system.
Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM25
Vulnerabilities
Page 2 of 2
CVE-2025-4758MEDIUMCVSS 6.9v1.12025-05-16
CVE-2025-4758 [MEDIUM] CWE-74 CVE-2025-4758: A vulnerability classified as critical has been found in PHPGurukul Beauty Parlour Management System
A vulnerability classified as critical has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected is an unknown function of the file /contact.php. The manipulation of the argument fname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters mi
cvelistv5nvd
CVE-2024-53480CRITICALCVSS 9.8v1.12024-12-10
CVE-2024-53480 [CRITICAL] CWE-89 CVE-2024-53480: Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via
Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter.
nvd
CVE-2024-53481MEDIUMCVSS 6.1v1.12024-12-10
CVE-2024-53481 [MEDIUM] CWE-79 CVE-2024-53481: A Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Managemen
A Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "Firstname" and "Last name" parameters.
nvd
CVE-2024-51065CRITICALCVSS 9.8v1.12024-10-31
CVE-2024-51065 [CRITICAL] CWE-89 CVE-2024-51065: Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php v
Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.
nvd
CVE-2024-51066HIGHCVSS 7.5v1.12024-10-31
CVE-2024-51066 [HIGH] CWE-639 CVE-2024-51066: An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's B
An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Management System v1.1 allows unauthorized access to the Personally Identifiable Information (PII) of other customers.
nvd
CVE-2024-37798MEDIUMCVSS 5.9v1.02024-06-17
CVE-2024-37798 [MEDIUM] CWE-79 CVE-2024-37798: Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul
Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Beauty Parlour Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input field.
nvd
CVE-2021-27544MEDIUMCVSS 4.8v1.02021-04-15
CVE-2021-27544 [MEDIUM] CWE-79 CVE-2021-27544: Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Manageme
Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "sername" parameter.
nvd
CVE-2021-27545MEDIUMCVSS 6.5v1.02021-04-15
CVE-2021-27545 [MEDIUM] CWE-89 CVE-2021-27545: SQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.
SQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to obtain sensitive database information by injecting SQL commands into the "sername" parameter.
nvd
← Previous2 / 2