Vulnerability Description
A HTML Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the fromdate and todate POST request parameters.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpgurukul | Park Ticketing Management System | 2.0 |
Related Weaknesses (CWE)
References
- https://github.com/rtnthakur/CVE/blob/main/PHPGurukul/Park-Ticketing-Management-ExploitThird Party Advisory
FAQ
What is CVE-2025-45010?
CVE-2025-45010 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A HTML Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute ...
How severe is CVE-2025-45010?
CVE-2025-45010 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-45010?
Check the references section above for vendor advisories and patch information. Affected products include: Phpgurukul Park Ticketing Management System.