4.3
CVSSv3

CVE-2025-5975

CVSSv4: 5.3 | CVSSv3: 4.3 | CVSSv2: 5 | VMScore: 630 | EPSS: 0.00028 | KEV: Not Included
Published: 10/06/2025 Updated: 10/06/2025

Vulnerability Summary

Cross-Site Scripting in PHPGurukul Rail Pass Management System 1.0

A vulnerability exists in PHPGurukul Rail Pass Management System 1.0 through the /rpms/download-pass.php file. An attacker can manipulate the searchdata argument to trigger a cross site scripting (XSS) attack. This vulnerability can be initiated remotely. The issue has been publicly disclosed and could potentially be exploited by malicious actors.

Vulnerable Product Search on Vulmon Subscribe to Product

phpgurukul rail pass management system