A Reflected Cross-Site Scripting (XSS) vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and User Management System V3.3. This vulnerability allows remote attackers to execute arbitrary JavaScript code via the fname, lname, and contact parameters.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 30 Sep 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A Reflected Cross-Site Scripting (XSS) vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and User Management System V3.3. This vulnerability allows remote attackers to execute arbitrary JavaScript code via the fname, lname, and contact parameters. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-30T14:33:13.418Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-28016

No data.

Status : Received
Published: 2025-09-30T15:15:48.950
Modified: 2025-09-30T15:15:48.950
Link: CVE-2025-28016

No data.

No data.