VYPR

User Management System

by Phpgurukul

CVEs (23)

  • CVE-2025-61255MedOct 21, 2025
    risk 0.40cvss 6.1epss 0.00

    Bank Locker Management System by PHPGurukul is affected by a Cross-Site Scripting (XSS) vulnerability via the /search parameter, where unsanitized input allows arbitrary HTML and JavaScript injection, potentially resulting in information disclosure and user redirection.

  • CVE-2024-50991MedNov 11, 2024
    risk 0.31cvss 4.8epss 0.00

    A Cross Site Scripting (XSS) vulnerability was found in /ums-sp/admin/registered-users.php in PHPGurukul User Management System v1.0, which allows remote attackers to execute arbitrary code via the "fname" POST request parameter

  • CVE-2023-0563LowJan 28, 2023
    risk 0.26cvss 3.5epss 0.38

    A vulnerability classified as problematic has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file add-locker-form.php of the component Assign Locker. The manipulation of the argument ahname leads to cross site scripting. It is…

Page 2 of 2