Cross-Site Request Forgery Vulnerability in PHPGurukul Student Result Management System
CVE-2025-56710

7.3HIGH

Key Information:

Vendor

PHPGurukul

Vendor
CVE Published:
15 September 2025

What is CVE-2025-56710?

A vulnerability has been identified in the Profile Page of PHPGurukul's Student-Result-Management-System-Using-PHP-V2.0, allowing attackers to exploit a Cross-Site Request Forgery (CSRF). This flaw enables malicious actors to craft deceptive HTML pages that trick authenticated users into modifying their account details without consent. As a result, unauthorized requests can be sent to the vulnerable endpoint, leading to potential account compromise.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.