CVE-2025-70899: CSRF
PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative forms. An attacker can perform unauthorized actions on behalf of authenticated administrators by tricking them into visiting a malicious webpage.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70899?
CVE-2025-70899 is classified as a high-severity vulnerability due to its potential for exploitation through Cross-Site Request Forgery.
How do I fix CVE-2025-70899?
To fix CVE-2025-70899, implement CSRF protection on all administrative forms within the PHPgurukul Online Course Registration application.
Who is affected by CVE-2025-70899?
CVE-2025-70899 affects users of PHPgurukul Online Course Registration version 3.1 who have administrative access.
What type of vulnerability is CVE-2025-70899?
CVE-2025-70899 is a Cross-Site Request Forgery (CSRF) vulnerability that allows unauthorized actions on behalf of authenticated users.
Can I exploit CVE-2025-70899 without authentication?
No, exploiting CVE-2025-70899 requires an attacker to trick an authenticated administrator into visiting a malicious webpage.