VYPR

Beauty Parlour Management System

by Phpgurukul

CVEs (28)

  • CVE-2025-4861HigMay 18, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument contactnumber leads to sql injection. The attack…

  • CVE-2025-4758HigMay 16, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected is an unknown function of the file /contact.php. The manipulation of the argument fname leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2025-4757HigMay 16, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in PHPGurukul Beauty Parlour Management System 1.1. It has been rated as critical. This issue affects some unknown processing of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack may be initiated…

  • CVE-2021-27545MedApr 15, 2021
    risk 0.42cvss 6.5epss 0.02

    SQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to obtain sensitive database information by injecting SQL commands into the "sername" parameter.

  • CVE-2025-11330MedOct 6, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. The affected element is an unknown function of the file /admin/sales-reports-detail.php. Such manipulation of the argument fromdate/todate leads to sql injection. The attack can be launched…

  • CVE-2024-53481MedDec 10, 2024
    risk 0.40cvss 6.1epss 0.00

    A Cross Site Scripting (XSS) vulnerability in the profile.php of PHPGurukul Beauty Parlour Management System v1.1 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "Firstname" and "Last name" parameters.

  • CVE-2024-37798MedJun 17, 2024
    risk 0.38cvss 5.9epss 0.00

    Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Beauty Parlour Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the search input field.

  • CVE-2021-27544MedApr 15, 2021
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "sername" parameter.

Page 2 of 2