CVE-2025-7924: PHPGurukul Online Banquet Booking System admin-profile.php cross site scripting
A vulnerability classified as problematic was found in PHPGurukul Online Banquet Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7924?
CVE-2025-7924 is classified as a problematic vulnerability with potential cross-site scripting implications.
How do I fix CVE-2025-7924?
To fix CVE-2025-7924, sanitize and validate the input for the adminname parameter in the /admin/admin-profile.php file.
What is the exploit type for CVE-2025-7924?
CVE-2025-7924 involves a cross-site scripting (XSS) vulnerability.
Which system is affected by CVE-2025-7924?
CVE-2025-7924 affects the PHPGurukul Online Banquet Booking System version 1.0.
What are the potential consequences of CVE-2025-7924?
Exploiting CVE-2025-7924 could allow attackers to execute arbitrary scripts in the context of a user's browser session.