CVE-2025-6288 Information

Description

A vulnerability which was classified as problematic has been found in PHPGurukul Bus Pass Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/admin-profile.php of the component Profile Page. The manipulation of the argument profile name leads to cross site scripting. The attack may be launched remotely.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N

Reference

https://phpgurukul.com/ https://vuldb.com/?ctiid.313292 https://vuldb.com/?id.313292 https://vuldb.com/?submit.593923

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction Required

HIGH

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

NONE

Base Severity

2.4

CNNVD-202506-2624 (Published: 2025-06-20)

Share on: