CVE-2025-9017: PHPGurukul Zoo Management System add-foreigner-ticket.php cross site scripting
A vulnerability has been found in PHPGurukul Zoo Management System 2.1. This vulnerability affects unknown code of the file /admin/add-foreigner-ticket.php. The manipulation of the argument visitorname leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9017?
CVE-2025-9017 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-9017?
To fix CVE-2025-9017, sanitize and validate user input for the 'visitorname' parameter in the affected file /admin/add-foreigner-ticket.php.
What type of vulnerability is CVE-2025-9017?
CVE-2025-9017 is a cross-site scripting (XSS) vulnerability that can be exploited to inject malicious scripts.
Who is affected by CVE-2025-9017?
CVE-2025-9017 affects users of PHPGurukul Zoo Management System version 2.1.
Can CVE-2025-9017 be exploited remotely?
Yes, CVE-2025-9017 can be exploited remotely, allowing an attacker to execute scripts in the context of a user's session.