VYPR
High severity7.3NVD Advisory· Published Sep 15, 2025· Updated Jun 17, 2026

CVE-2025-56710

CVE-2025-56710

Description

A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Management-System-Using-PHP-V2.0. This flaw allows an attacker to trick authenticated users into unintentionally modifying their account details. By crafting a malicious HTML page, an attacker can submit unauthorized requests to the vulnerable endpoint: /create-class.php.

Affected products

3
  • cpe:2.3:a:phpgurukul:student_result_management_system:2.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:phpgurukul:student_result_management_system:2.0:*:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: = 2.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.