A flaw has been found in PHPGurukul Car Rental Project 3.0. Affected by this issue is some unknown functionality of the file /carrental/search.php. Executing manipulation of the argument autofocus can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.
References
Link | Resource |
---|---|
https://github.com/tddgns/cve/issues/1 | Exploit Issue Tracking Third Party Advisory |
https://phpgurukul.com/ | Product |
https://vuldb.com/?ctiid.325151 | Permissions Required VDB Entry |
https://vuldb.com/?id.325151 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.654067 | Third Party Advisory VDB Entry |
Configurations
History
25 Sep 2025, 19:16
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/tddgns/cve/issues/1 - Exploit, Issue Tracking, Third Party Advisory | |
References | () https://phpgurukul.com/ - Product | |
References | () https://vuldb.com/?ctiid.325151 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.325151 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.654067 - Third Party Advisory, VDB Entry | |
First Time |
Phpgurukul car Rental Project
Phpgurukul |
|
CPE | cpe:2.3:a:phpgurukul:car_rental_project:3.0:*:*:*:*:*:*:* |
22 Sep 2025, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-22 11:15
Updated : 2025-09-25 19:16
NVD link : CVE-2025-10794
Mitre link : CVE-2025-10794
CVE.ORG link : CVE-2025-10794
JSON object : View
Products Affected
phpgurukul
- car_rental_project