CVE-2025-70899
EUVD-2026-387622.01.2026, 17:16
PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative forms. An attacker can perform unauthorized actions on behalf of authenticated administrators by tricking them into visiting a malicious webpage.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| phpgurukul | online_course_registration | 3.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration