High severity7.3NVD Advisory· Published Sep 15, 2025· Updated Jun 17, 2026
CVE-2025-56710
CVE-2025-56710
Description
A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Management-System-Using-PHP-V2.0. This flaw allows an attacker to trick authenticated users into unintentionally modifying their account details. By crafting a malicious HTML page, an attacker can submit unauthorized requests to the vulnerable endpoint: /create-class.php.
Affected products
3cpe:2.3:a:phpgurukul:student_result_management_system:2.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:phpgurukul:student_result_management_system:2.0:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: = 2.0
Patches
Vulnerability mechanics
References
1- medium.com/@mrshaikh841/csrf-pocs-1c96d9305298nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.