CVE-2026-3402

A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0. This vulnerability affects unknown code of the file /edit-course.php. Such manipulation of the argument Course Short Name leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
References
Link Resource
https://github.com/AS-AbdulSamad/CVEs/issues/2 Exploit Third Party Advisory Issue Tracking
https://phpgurukul.com/ Product
https://vuldb.com/?ctiid.348297 Permissions Required VDB Entry
https://vuldb.com/?id.348297 Third Party Advisory VDB Entry
https://vuldb.com/?submit.763323 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpgurukul:student_record_system:1.0:*:*:*:*:*:*:*

History

03 Mar 2026, 19:47

Type Values Removed Values Added
First Time Phpgurukul student Record System
Phpgurukul
CPE cpe:2.3:a:phpgurukul:student_record_system:1.0:*:*:*:*:*:*:*
References () https://github.com/AS-AbdulSamad/CVEs/issues/2 - () https://github.com/AS-AbdulSamad/CVEs/issues/2 - Exploit, Third Party Advisory, Issue Tracking
References () https://phpgurukul.com/ - () https://phpgurukul.com/ - Product
References () https://vuldb.com/?ctiid.348297 - () https://vuldb.com/?ctiid.348297 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.348297 - () https://vuldb.com/?id.348297 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.763323 - () https://vuldb.com/?submit.763323 - Third Party Advisory, VDB Entry

02 Mar 2026, 20:30

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad de seguridad en PHPGurukul Student Record Management System hasta la versión 1.0, la cual afecta a código desconocido del archivo /edit-course.php. Manipular el argumento Course Short Name provoca un cross site scripting. El ataque puede ser ejecutado en remoto. El exploit ha sido divulgado públicamente y puede ser usado.

02 Mar 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-02 01:16

Updated : 2026-03-03 19:47


NVD link : CVE-2026-3402

Mitre link : CVE-2026-3402

CVE.ORG link : CVE-2026-3402


JSON object : View

Products Affected

phpgurukul

  • student_record_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')