CVE-2025-9656: PHPGurukul Directory Management System add-directory.php cross site scripting
A security vulnerability has been detected in PHPGurukul Directory Management System 2.0. This vulnerability affects unknown code of the file /admin/add-directory.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9656?
CVE-2025-9656 has a medium severity level due to the potential for cross-site scripting attacks.
How do I fix CVE-2025-9656?
To fix CVE-2025-9656, validate and sanitize all input data on the /admin/add-directory.php file to prevent the manipulation of the fullname argument.
Who is affected by CVE-2025-9656?
CVE-2025-9656 affects users of PHPGurukul Directory Management System version 2.0.
What are the potential impacts of CVE-2025-9656?
The potential impacts of CVE-2025-9656 include unauthorized script execution and possible data theft through cross-site scripting.
Can CVE-2025-9656 be exploited remotely?
Yes, CVE-2025-9656 can be exploited remotely by an attacker targeting the affected PHPGurukul Directory Management System.