Medium severity6.5NVD Advisory· Published Jan 22, 2026· Updated Jun 17, 2026
CVE-2025-70899
CVE-2025-70899
Description
PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative forms. An attacker can perform unauthorized actions on behalf of authenticated administrators by tricking them into visiting a malicious webpage.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:phpgurukul:online_course_registration:3.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:phpgurukul:online_course_registration:3.1:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: = 3.1
Patches
Vulnerability mechanics
References
2- github.com/mathavamoorthi/CVE-2025-70899/blob/main/Missing_CSRF_protection_poc.mdnvdExploitMitigationThird Party Advisory
- phpgurukul.com/online-course-registration-free-download/nvdProduct
News mentions
0No linked articles in our index yet.