CVE-2025-6126: PHPGurukul Rail Pass Management System contact.php cross site scripting
A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /contact.php. The manipulation of the argument Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6126?
The vulnerability CVE-2025-6126 is categorized as problematic, indicating a significant security risk.
How do I fix CVE-2025-6126?
To mitigate CVE-2025-6126, it is essential to sanitize and validate user inputs in the /contact.php file to prevent cross-site scripting attacks.
What type of vulnerability is CVE-2025-6126?
CVE-2025-6126 is a Cross-Site Scripting (XSS) vulnerability resulting from improper handling of user input in the Rail Pass Management System.
Which software is affected by CVE-2025-6126?
CVE-2025-6126 affects PHPGurukul Rail Pass Management System version 1.0.
What is the main attack vector for CVE-2025-6126?
The main attack vector for CVE-2025-6126 is the manipulation of the 'Name' argument in the /contact.php file.