A Reflected Cross-Site Scripting (XSS) vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and User Management System V3.3. This vulnerability allows remote attackers to execute arbitrary JavaScript code via the fname, lname, and contact parameters.
Metrics
Affected Vendors & Products
References
History
Tue, 07 Oct 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Phpgurukul user Registration \& Login And User Management System
|
|
CPEs | cpe:2.3:a:phpgurukul:user_registration_\&_login_and_user_management_system:3.3:*:*:*:*:*:*:* | |
Vendors & Products |
Phpgurukul user Registration \& Login And User Management System
|
Thu, 02 Oct 2025 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Phpgurukul
Phpgurukul user Registration And Login And User Management System |
|
Vendors & Products |
Phpgurukul
Phpgurukul user Registration And Login And User Management System |
Tue, 30 Sep 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Tue, 30 Sep 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A Reflected Cross-Site Scripting (XSS) vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and User Management System V3.3. This vulnerability allows remote attackers to execute arbitrary JavaScript code via the fname, lname, and contact parameters. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-30T19:29:13.883Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-28016

Updated: 2025-09-30T19:28:44.926Z

Status : Analyzed
Published: 2025-09-30T15:15:48.950
Modified: 2025-10-07T13:42:23.450
Link: CVE-2025-28016

No data.