CVE-2025-45015

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Apr 30, 2025
Updated: May 9, 2025
CWE ID 79

Summary

CVE-2025-45015 is a Cross-Site Scripting (XSS) vulnerability identified in the PHPGurukul Park Ticketing Management System version 2.0. The issue resides in the foreigner-bwdates-reports-details.php file and enables remote attackers to inject malicious JavaScript code through the fromdate and todate parameters. Successful exploitation of this vulnerability may lead to unintended execution of attacker-supplied code in a user's web browser, potentially compromising sensitive information or taking control of the affected session. It is highly recommended that users upgrade to the latest available version of the PHPGurukul Park Ticketing Management System to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share