cbcvebase.

Phpgurukul Student Record System vulnerabilities

29 known vulnerabilities affecting phpgurukul/student_record_system.

Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH11MEDIUM10

Vulnerabilities

Page 2 of 2
CVE-2024-44632P3MEDIUMCVSS 6.5v3.202025-11-14
CVE-2024-44632 [MEDIUM] CWE-89 CVE-2024-44632: PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid paramete PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recovery.php.
nvd
CVE-2024-44633P3MEDIUMCVSS 6.5v3.202025-11-14
CVE-2024-44633 [MEDIUM] CWE-89 CVE-2024-44633: PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword paramet PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword parameter in change-password.php.
nvd
CVE-2024-44636P3MEDIUMCVSS 6.5v3.202025-11-14
CVE-2024-44636 [MEDIUM] CWE-89 CVE-2024-44636: PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid parameters in /admin-profile.php.
nvd
CVE-2025-63955P3HIGHCVSS 7.5v3.22025-11-18
CVE-2025-63955 [HIGH] CWE-352 CVE-2025-63955: A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request. This leads to the unauthorized deletion of user accounts, causing a Denial of Service (DoS).
nvd
CVE-2024-55016P3MEDIUMCVSS 6.5v3.202025-11-14
CVE-2024-55016 [MEDIUM] CWE-89 CVE-2024-55016: PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and passw PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php.
nvd
CVE-2024-27685P3HIGHCVSS 7.1v3.202025-06-25
CVE-2024-27685 [HIGH] CWE-89 CVE-2024-27685: SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote atta SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensitive information via a crafted payload to the $cshortname, $cfullname, and $cdate variables.
nvd
CVE-2024-44635P4MEDIUMCVSS 6.1v3.202025-11-14
CVE-2024-44635 [MEDIUM] CWE-79 CVE-2024-44635: PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and PHPGurukul Student Record System 3.20 is vulnerable to Cross Site Scripting (XSS) via adminname and aemailid parameters in /admin-profile.php.
nvd
CVE-2026-3402P4MEDIUMCVSS 4.8v1.02026-03-02
CVE-2026-3402 [MEDIUM] CWE-79 CVE-2026-3402: A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0. A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0. This vulnerability affects unknown code of the file /edit-course.php. Such manipulation of the argument Course Short Name leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
nvd
CVE-2026-3403P4MEDIUMCVSS 4.8v1.02026-03-02
CVE-2026-3403 [MEDIUM] CWE-79 CVE-2026-3403: A vulnerability was detected in PHPGurukul Student Record Management System 1.0. This issue affects A vulnerability was detected in PHPGurukul Student Record Management System 1.0. This issue affects some unknown processing of the file /edit-subject.php. Performing a manipulation of the argument Subject 1 results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.
nvd
Phpgurukul Student Record System vulnerabilities | cvebase