VYPR

Student Record System

by Phpgurukul

CVEs (32)

  • CVE-2021-26765CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.03

    SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid parameter to edit-sub.php.

  • CVE-2021-26764HigJul 22, 2021
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in PHPGurukul Student Record System v 4.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit-std.php.

  • CVE-2021-26762HigJul 22, 2021
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the cid parameter to edit-course.php.

  • CVE-2025-63955HigNov 18, 2025
    risk 0.49cvss 7.5epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request. This leads to the unauthorized deletion of user accounts,…

  • CVE-2024-9091HigSep 23, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in code-projects Student Record System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument regno leads to sql injection. The attack can be launched…

  • CVE-2024-9080HigSep 22, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in code-projects Student Record System 1.0. It has been classified as critical. Affected is an unknown function of the file /pincode-verification.php. The manipulation of the argument pincode leads to sql injection. It is possible to launch the attack…

  • CVE-2024-9079HigSep 22, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in code-projects Student Record System 1.0 and classified as critical. This issue affects some unknown processing of the file /marks.php. The manipulation of the argument coursename leads to sql injection. The attack may be initiated remotely. The…

  • CVE-2024-3769HigApr 15, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an unknown function of the file /login.php. The manipulation of the argument id/password leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2025-5216HigMay 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical was found in PHPGurukul Student Record System 3.20. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2025-4112HigApr 30, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul Student Record System 3.20. It has been declared as critical. This vulnerability affects unknown code of the file /add-course.php. The manipulation of the argument course-short leads to sql injection. The attack can be initiated remotely.…

  • CVE-2025-4108HigApr 30, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an unknown function of the file /add-subject.php. The manipulation of the argument sub1 leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2025-4073HigApr 29, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul Student Record System 3.20. It has been classified as critical. Affected is an unknown function of the file /change-password.php. The manipulation of the argument currentpassword leads to sql injection. It is possible to launch the attack…

  • CVE-2025-1902HigMar 4, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability affects unknown code of the file /password-recovery.php. The manipulation of the argument emailid leads to sql injection. The attack can be initiated remotely.…

  • CVE-2024-27685HigJun 25, 2025
    risk 0.46cvss 7.1epss 0.00

    SQL Injection vulnerability in Student Record system Using PHP and MySQL v.3.20 allows a remote attacker to obtain sensitive information via a crafted payload to the $cshortname, $cfullname, and $cdate variables.

  • CVE-2024-55016MedNov 14, 2025
    risk 0.42cvss 6.5epss 0.00

    PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php.

  • CVE-2024-44640MedNov 14, 2025
    risk 0.42cvss 6.5epss 0.00

    PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the course-short, course-full, and cdate parameters in add-course.php.

  • CVE-2024-44639MedNov 14, 2025
    risk 0.42cvss 6.5epss 0.00

    PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the sub1, sub2, sub3, sub4, and course-short parameters in add-subject.php.

  • CVE-2024-44636MedNov 14, 2025
    risk 0.42cvss 6.5epss 0.00

    PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the adminname and aemailid parameters in /admin-profile.php.

  • CVE-2024-44633MedNov 14, 2025
    risk 0.42cvss 6.5epss 0.00

    PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword parameter in change-password.php.

  • CVE-2024-44632MedNov 14, 2025
    risk 0.42cvss 6.5epss 0.00

    PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the id and emailid parameters in password-recovery.php.

Page 1 of 2