CVE-2025-28015 - CERT CVE
ID CVE-2025-28015
Sažetak A HTML Injection vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and User Management System V3.3. This vulnerability allows remote attackers to execute arbitrary HTML code via the fname, lname, and contact parameters.
Reference
CVSS
Base: 5.3
Impact: 4.7
Exploitability:0.6
Pristup
VektorSloženostAutentikacija
LOCAL LOW HIGH
Impact
PovjerljivostCjelovitostDostupnost
HIGH LOW LOW
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L
Zadnje važnije ažuriranje 28-03-2025 - 19:49
Objavljeno 13-03-2025 - 16:15