📦 Student Record System

by Phpgurukul

🔍 What is Student Record System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-26765

CRITICAL CVSS 9.8 Jul 22, 2021

CVE-2021-26765 is a critical SQL injection vulnerability in PHPGurukul Student Record System 4.0 that allows remote attackers to execute arbitrary SQL commands via the sid parameter in edit-sub.php. T...

CVE-2025-63955

HIGH CVSS 7.5 Nov 18, 2025

A CSRF vulnerability in PHPGurukul Student Record System v3.2 allows attackers to trick authenticated administrators into executing unauthorized account deletion requests. This leads to denial of serv...

CVE-2025-4112

HIGH CVSS 7.3 Apr 30, 2025

This critical SQL injection vulnerability in PHPGurukul Student Record System allows remote attackers to execute arbitrary SQL commands via the 'course-short' parameter in /add-course.php. This affect...

CVE-2025-4108

HIGH CVSS 7.3 Apr 30, 2025

This critical vulnerability in PHPGurukul Student Record System allows remote attackers to execute arbitrary SQL commands via the 'sub1' parameter in /add-subject.php. Successful exploitation could le...

CVE-2025-4073

HIGH CVSS 7.3 Apr 29, 2025

This critical SQL injection vulnerability in PHPGurukul Student Record System 3.20 allows attackers to manipulate database queries through the change-password.php file. Remote attackers can potentiall...

CVE-2024-3769

HIGH CVSS 7.3 Apr 15, 2024

This critical vulnerability in PHPGurukul Student Record System 3.20 allows SQL injection through the login.php page, potentially enabling authentication bypass and unauthorized database access. Attac...

CVE-2021-26762

HIGH CVSS 8.8 Jul 22, 2021

This SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements via the cid parameter in edit-course.php. This can lead to unauthor...

CVE-2024-44636

MEDIUM CVSS 6.5 Nov 14, 2025

This SQL injection vulnerability in PHPGurukul Student Record System 3.20 allows attackers to manipulate database queries through the adminname and aemailid parameters in /admin-profile.php. Attackers...

CVE-2024-44639

MEDIUM CVSS 6.5 Nov 14, 2025

PHPGurukul Student Record System 3.20 contains SQL injection vulnerabilities in the add-subject.php file through multiple parameters (sub1, sub2, sub3, sub4, course-short). Attackers can execute arbit...

CVE-2024-44640

MEDIUM CVSS 6.5 Nov 14, 2025

CVE-2024-44640 is an SQL injection vulnerability in PHPGurukul Student Record System that allows attackers to manipulate database queries through course-related parameters. This affects administrators...

CVE-2024-55016

MEDIUM CVSS 6.5 Nov 14, 2025

This SQL injection vulnerability in PHPGurukul Student Record Management System allows attackers to manipulate database queries through the login page. Any organization using version 3.20 of this syst...

CVE-2024-44630

MEDIUM CVSS 6.5 Nov 14, 2025

This CVE describes SQL injection vulnerabilities in multiple parameters of the register.php file in PHPGurukul Student Record System 3.20. Attackers can inject malicious SQL queries through user input...

CVE-2024-44632

MEDIUM CVSS 6.5 Nov 14, 2025

PHPGurukul Student Record System 3.20 contains SQL injection vulnerabilities in the password recovery functionality. Attackers can manipulate the id and emailid parameters in password-recovery.php to ...

CVE-2024-44633

MEDIUM CVSS 6.5 Nov 14, 2025

This vulnerability allows attackers to execute arbitrary SQL commands via the currentpassword parameter in change-password.php. It affects PHPGurukul Student Record System 3.20 installations, potentia...

CVE-2024-44635

MEDIUM CVSS 6.1 Nov 14, 2025

This vulnerability allows attackers to inject malicious scripts into the PHPGurukul Student Record System admin profile page. When exploited, it can lead to session hijacking, credential theft, or una...

CVE-2025-6915

MEDIUM CVSS 6.3 Jun 30, 2025

A critical SQL injection vulnerability exists in PHPGurukul Student Record System 3.2's /register.php file, allowing remote attackers to manipulate database queries through the session parameter. This...

CVE-2025-6913

MEDIUM CVSS 6.3 Jun 30, 2025

A critical SQL injection vulnerability exists in PHPGurukul Student Record System 3.2 through the /admin-profile.php file's aemailid parameter. This allows remote attackers to execute arbitrary SQL co...

CVE-2025-6911

MEDIUM CVSS 6.3 Jun 30, 2025

This critical SQL injection vulnerability in PHPGurukul Student Record System 3.2 allows attackers to execute arbitrary SQL commands via the 'del' parameter in /manage-subjects.php. Remote attackers c...