CVE-2025-45010
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Apr 30, 2025
Updated: May 9, 2025
CWE ID 77
Summary
CVE-2025-45010 is a newly identified HTML Injection vulnerability affecting the PHPGurukul Park Ticketing Management System version 2.0. The flaw lies in the normal-bwdates-reports-details.php file, where attackers can exploit the fromdate and todate POST request parameters to inject malicious HTML code. Successful exploitation enables remote code execution, posing a significant security risk. System administrators should immediately patch their systems to mitigate this vulnerability and prevent potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.