CVE-2023-6653
PHPGurukul Teacher Subject Allocation Management System Create a new Subject subject.php cross-site request forgery
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.3EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
10 Dec 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability was found in PHPGurukul Teacher Subject Allocation Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/subject.php of the component Create a new Subject. The manipulation of the argument cid leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-247346 is the identifier assigned to this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Affected products
PHPGurukul · Teacher Subject Allocation Management SystemWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →