Phpgurukul Online Security Guards Hiring System vulnerabilities

8 known vulnerabilities affecting phpgurukul/online_security_guards_hiring_system.

Total CVEs
8
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM7

Vulnerabilities

Page 1 of 1
CVE-2025-7791MEDIUMCVSS 5.1v1.02025-07-18
CVE-2025-7791 [MEDIUM] CWE-79 CVE-2025-7791: A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0. It has been declar A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/search.php. The manipulation of the argument searchdata leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and ma
cvelistv5nvd
CVE-2025-3138MEDIUMCVSS 6.9v1.02025-04-03
CVE-2025-3138 [MEDIUM] CWE-74 CVE-2025-3138: A vulnerability has been found in PHPGurukul Online Security Guards Hiring System 1.0 and classified A vulnerability has been found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-guard-detail.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the
cvelistv5nvd
CVE-2025-3137MEDIUMCVSS 6.9v1.02025-04-03
CVE-2025-3137 [MEDIUM] CWE-74 CVE-2025-3137: A vulnerability, which was classified as critical, was found in PHPGurukul Online Security Guards Hi A vulnerability, which was classified as critical, was found in PHPGurukul Online Security Guards Hiring System 1.0. Affected is an unknown function of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be use
cvelistv5nvd
CVE-2025-2658MEDIUMCVSS 6.9v1.02025-03-23
CVE-2025-2658 [MEDIUM] CWE-74 CVE-2025-2658: A vulnerability, which was classified as critical, has been found in PHPGurukul Online Security Guar A vulnerability, which was classified as critical, has been found in PHPGurukul Online Security Guards Hiring System 1.0. Affected by this issue is some unknown functionality of the file /search-request.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the pub
cvelistv5nvd
CVE-2025-2665MEDIUMCVSS 6.9v1.02025-03-23
CVE-2025-2665 [MEDIUM] CWE-74 CVE-2025-2665: A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0. It has been classi A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the
cvelistv5nvd
CVE-2023-39551CRITICALCVSS 9.8v1.02023-08-04
CVE-2023-39551 [CRITICAL] CWE-89 CVE-2023-39551: PHPGurukul Online Security Guards Hiring System v.1.0 is vulnerable to SQL Injection via osghs/admin PHPGurukul Online Security Guards Hiring System v.1.0 is vulnerable to SQL Injection via osghs/admin/search.php.
nvd
CVE-2023-36936MEDIUMCVSS 6.1v1.02023-07-10
CVE-2023-36936 [MEDIUM] CWE-79 CVE-2023-36936: Cross-Site Scripting (XSS) vulnerability in PHPGurukul Online Security Guards Hiring System using PH Cross-Site Scripting (XSS) vulnerability in PHPGurukul Online Security Guards Hiring System using PHP and MySQL 1.0 allows attackers to execute arbitrary code via a crafted payload to the search booking box.
nvd
CVE-2023-0527MEDIUMCVSS 6.1PoCv1.02023-01-27
CVE-2023-0527 [LOW] CWE-79 CVE-2023-0527: A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as p A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file search-request.php. The manipulation of the argument searchdata with the input ">alert(document.domain) leads to cross site scripting. The attack may be launched remotely. The expl
cvelistv5nvd