📦 Rail Pass Management System

by Phpgurukul

🔍 What is Rail Pass Management System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-5553

HIGH CVSS 7.3 Jun 4, 2025

This critical SQL injection vulnerability in PHPGurukul Rail Pass Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the searchdata parameter in /download-pass.php. Th...

CVE-2025-4070

HIGH CVSS 7.3 Apr 29, 2025

This critical SQL injection vulnerability in PHPGurukul Rail Pass Management System 1.0 allows attackers to manipulate database queries via the editid parameter in /admin/changeimage.php. Attackers ca...

CVE-2025-4039

HIGH CVSS 7.3 Apr 28, 2025

This critical SQL injection vulnerability in PHPGurukul Rail Pass Management System 1.0 allows attackers to execute arbitrary SQL commands via the searchdata parameter in /admin/search-pass.php. Attac...

CVE-2023-31932

HIGH CVSS 7.2 Jul 28, 2023

This SQL injection vulnerability in Rail Pass Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the viewid parameter. Attackers can potentially read, modify, or dele...

CVE-2023-31936

HIGH CVSS 7.2 Jul 28, 2023

This SQL injection vulnerability in Rail Pass Management System v1.0 allows remote attackers to execute arbitrary SQL commands via the viewid parameter. Attackers can potentially read, modify, or dele...

CVE-2025-6126

MEDIUM CVSS 4.3 Jun 16, 2025

This is a cross-site scripting (XSS) vulnerability in PHPGurukul Rail Pass Management System 1.0 that allows attackers to inject malicious scripts via the Name parameter in contact.php. The vulnerabil...

CVE-2025-5975

MEDIUM CVSS 4.3 Jun 10, 2025

This cross-site scripting (XSS) vulnerability in PHPGurukul Rail Pass Management System allows attackers to inject malicious scripts via the 'searchdata' parameter in the /rpms/download-pass.php file....

CVE-2025-5554

MEDIUM CVSS 6.3 Jun 4, 2025

This critical vulnerability in PHPGurukul Rail Pass Management System 1.0 allows remote attackers to execute SQL injection attacks via the fromdate/todate parameters in the /admin/pass-bwdates-reports...