A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Management-System-Using-PHP-V2.0. This flaw allows an attacker to trick authenticated users into unintentionally modifying their account details. By crafting a malicious HTML page, an attacker can submit unauthorized requests to the vulnerable endpoint: /create-class.php.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://medium.com/@mrshaikh841/csrf-pocs-1c96d9305298 |
|
History
Mon, 22 Sep 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:phpgurukul:student_result_management_system:2.0:*:*:*:*:*:*:* |
Wed, 17 Sep 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phpgurukul
Phpgurukul student Result Management System |
|
| Vendors & Products |
Phpgurukul
Phpgurukul student Result Management System |
Mon, 15 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 | |
| Metrics |
cvssV3_1
|
Mon, 15 Sep 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Management-System-Using-PHP-V2.0. This flaw allows an attacker to trick authenticated users into unintentionally modifying their account details. By crafting a malicious HTML page, an attacker can submit unauthorized requests to the vulnerable endpoint: /create-class.php. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-09-15T00:00:00.000Z
Updated: 2025-09-15T14:07:16.482Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-56710
Updated: 2025-09-15T14:06:47.820Z
Status : Analyzed
Published: 2025-09-15T14:15:43.867
Modified: 2025-09-20T02:51:37.760
Link: CVE-2025-56710
No data.