A flaw has been found in PHPGurukul Online Course Registration up to 3.1. This affects an unknown function. This manipulation causes missing authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/rsecroot/Online-Course-Registration/blob/main/Broken%20Access%20Control.md | Exploit Third Party Advisory |
| https://phpgurukul.com/ | Product |
| https://vuldb.com/?ctiid.339326 | Permissions Required VDB Entry |
| https://vuldb.com/?id.339326 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.728354 | Third Party Advisory VDB Entry |
Configurations
History
06 Jan 2026, 18:37
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Phpgurukul online Course Registration
Phpgurukul |
|
| CPE | cpe:2.3:a:phpgurukul:online_course_registration:*:*:*:*:*:*:*:* | |
| References | () https://github.com/rsecroot/Online-Course-Registration/blob/main/Broken%20Access%20Control.md - Exploit, Third Party Advisory | |
| References | () https://phpgurukul.com/ - Product | |
| References | () https://vuldb.com/?ctiid.339326 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.339326 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.728354 - Third Party Advisory, VDB Entry |
01 Jan 2026, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-01 17:15
Updated : 2026-01-06 18:37
NVD link : CVE-2025-15406
Mitre link : CVE-2025-15406
CVE.ORG link : CVE-2025-15406
JSON object : View
Products Affected
phpgurukul
- online_course_registration
