CVE-2025-28015
MEDIUMPhpgurukul User Registration & Login ... - Basic XSS
Title source: ruleDescription
A HTML Injection vulnerability was found in loginsystem/edit-profile.php of the PHPGurukul User Registration & Login and User Management System V3.3. This vulnerability allows remote attackers to execute arbitrary HTML code via the fname, lname, and contact parameters.
Scores
CVSS v3
5.3
EPSS
0.0033
EPSS Percentile
55.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-80
Status
published
Products (1)
phpgurukul/user_registration_\&_login_and_user_management_system
3.3
Published
Mar 13, 2025
Tracked Since
Feb 18, 2026