{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-2375","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2025-03-16T13:19:12.784Z","datePublished":"2025-03-17T11:31:06.000Z","dateUpdated":"2025-03-17T16:06:21.510Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2025-03-17T11:31:06.000Z"},"title":"PHPGurukul Human Metapneumovirus Testing Management System Admin Profile Page profile.php cross site scripting","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-79","lang":"en","description":"Cross Site Scripting"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-94","lang":"en","description":"Code Injection"}]}],"affected":[{"vendor":"PHPGurukul","product":"Human Metapneumovirus Testing Management System","versions":[{"version":"1.0","status":"affected"}],"modules":["Admin Profile Page"]}],"descriptions":[{"lang":"en","value":"A vulnerability, which was classified as problematic, was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. Affected is an unknown function of the file /profile.php of the component Admin Profile Page. The manipulation of the argument email leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used."},{"lang":"de","value":"Es wurde eine Schwachstelle in PHPGurukul Human Metapneumovirus Testing Management System 1.0 gefunden. Sie wurde als problematisch eingestuft. Betroffen hiervon ist ein unbekannter Ablauf der Datei /profile.php der Komponente Admin Profile Page. Durch die Manipulation des Arguments email mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.1,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":3.5,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"}},{"cvssV3_0":{"version":"3.0","baseScore":3.5,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"}},{"cvssV2_0":{"version":"2.0","baseScore":4,"vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N"}}],"timeline":[{"time":"2025-03-16T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2025-03-16T01:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2025-03-16T14:24:17.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"WenGui (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.299874","name":"VDB-299874 | PHPGurukul Human Metapneumovirus Testing Management System Admin Profile Page profile.php cross site scripting","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.299874","name":"VDB-299874 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.515444","name":"Submit #515444 | PHPGurukul Human Metapneumovirus Testing Management System profile.php Stored cross-site scripting","tags":["third-party-advisory"]},{"url":"https://github.com/SECWG/cve/issues/8","tags":["exploit","issue-tracking"]},{"url":"https://phpgurukul.com/","tags":["product"]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-03-17T16:03:04.822919Z","id":"CVE-2025-2375","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-03-17T16:06:21.510Z"}}]}}