CVE-2026-3402

A security vulnerability has been detected in PHPGurukul Student Record Management System up to 1.0. This vulnerability affects unknown code of the file /edit-course.php. Such manipulation of the argument Course Short Name leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
References
Link Resource
https://github.com/AS-AbdulSamad/CVEs/issues/2 Exploit Third Party Advisory Issue Tracking
https://phpgurukul.com/ Product
https://vuldb.com/?ctiid.348297 Permissions Required VDB Entry
https://vuldb.com/?id.348297 Third Party Advisory VDB Entry
https://vuldb.com/?submit.763323 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpgurukul:student_record_system:1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-02 01:16

Updated : 2026-03-03 19:47


NVD link : CVE-2026-3402

Mitre link : CVE-2026-3402

CVE.ORG link : CVE-2026-3402


JSON object : View

Products Affected

phpgurukul

  • student_record_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')