CVE-2025-45015
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2025-45015 is a Cross-Site Scripting (XSS) vulnerability identified in the PHPGurukul Park Ticketing Management System version 2.0. The issue resides in the foreigner-bwdates-reports-details.php file and enables remote attackers to inject malicious JavaScript code through the fromdate and todate parameters. Successful exploitation of this vulnerability may lead to unintended execution of attacker-supplied code in a user's web browser, potentially compromising sensitive information or taking control of the affected session. It is highly recommended that users upgrade to the latest available version of the PHPGurukul Park Ticketing Management System to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.