VYPR

Student Result Management System

by Phpgurukul

CVEs (14)

  • CVE-2023-48722CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_results.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-48720CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-48718CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_students.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2024-55270HigFeb 17, 2026
    risk 0.57cvss 8.8epss 0.00

    phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter.

  • CVE-2025-50489HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack.

  • CVE-2025-50490HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management System v2.0 allows attackers to execute a session hijacking attack.

  • CVE-2025-56710HigSep 15, 2025
    risk 0.47cvss 7.3epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Management-System-Using-PHP-V2.0. This flaw allows an attacker to trick authenticated users into unintentionally modifying their account details. By crafting a…

  • CVE-2025-7534HigJul 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in PHPGurukul Student Result Management System 2.0. It has been classified as critical. Affected is an unknown function of the file /notice-details.php of the component GET Parameter Handler. The manipulation of the argument nid leads to sql injection.…

  • CVE-2025-5599HigJun 4, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical was found in PHPGurukul Student Result Management System 1.3. This vulnerability affects unknown code of the file /editmyexp.php. The manipulation of the argument emp1ctc leads to sql injection. The attack can be initiated remotely. The…

  • CVE-2024-55016MedNov 14, 2025
    risk 0.42cvss 6.5epss 0.00

    PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php.

  • CVE-2024-51103MedMay 23, 2025
    risk 0.42cvss 6.5epss 0.00

    PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabilities at /studentrecordms/password-recovery.php via the emailid and id parameters.

  • CVE-2023-33580MedJun 26, 2023
    risk 0.34cvss 4.8epss 0.04

    Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" field on Admin Profile page.

  • CVE-2025-5232MedMay 27, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability, which was classified as critical, has been found in PHPGurukul Student Study Center Management System 1.0. This issue affects some unknown processing of the file /admin/report.php. The manipulation of the argument fromdate/todate leads to sql injection. The…

  • CVE-2024-51102MedMay 23, 2025
    risk 0.29cvss 4.4epss 0.00

    PHPGURUKUL Student Management System using PHP and MySQL v1 was discovered to contain multiple SQL injection vulnerabilities at /studentrecordms/login.php via the username and password parameters.