github.comexploitissue tracking
https://github.com/f1rstb100d/CVE/issues/44 CVE-2026-6162
MEDIUM
PHPGurukul Company Visitor Management System bwdates-reports-details.php cross site scripting
Record summary
CVE-2026-6162 has a selected CVSS score of 5.1 (medium).
Description
A vulnerability has been found in PHPGurukul Company Visitor Management System 2.0. This impacts an unknown function of the file /bwdates-reports-details.php. The manipulation of the argument fromdate leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 13, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Company Visitor Management SystemBrowse PHPGurukul / Company Visitor Management System | CVE List | 2.0 | affected |
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-6162 phpgurukul.comproduct
https://phpgurukul.com/ Submit #797171 | PHPGurukul Company Visitors Management System 2.0 Cross Site ScriptingThird-party advisory
https://vuldb.com/submit/797171 VDB-357048 | PHPGurukul Company Visitor Management System bwdates-reports-details.php cross site scriptingvdb entryTechnical description
https://vuldb.com/vuln/357048 VDB-357048 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/vuln/357048/cti