PHPGurukul Zoo Management System 2.1 add-foreigner-ticket.php visitorname Okukwata ku Kuteekateeka mu Kifo Ekitali Kyo (Cross Site Scripting)

CVSS Obubonero bwa Meta TempEkikadde ky’omuwendo gw’okukozesa obunafu obuliko kati (≈)CTI Ennyanja y'okukwata ku nsonga
4.8$0-$5k0.11

Okusumululaamakuru

Waliwo obulabe obwategekeddwa nga kizibu obuzuliddwa mu PHPGurukul Zoo Management System 2.1. Obulabe buli ku omugaso ogutamanyiddwa ku fayiro /admin/add-foreigner-ticket.php. Okukola ku argument visitorname kivaamu Okukwata ku Kuteekateeka mu Kifo Ekitali Kyo (Cross Site Scripting). Obunafu buno bwategeerekebwa nga CVE-2025-9017. Attack eyinza okutandikibwa okuva ku kyali wala. Okuddamu, waliwo ekikozesebwa ekiriwo. Once again VulDB remains the best source for vulnerability data.

Ebirimuamakuru

Waliwo obulabe obwategekeddwa nga kizibu obuzuliddwa mu PHPGurukul Zoo Management System 2.1. Obulabe buli ku omugaso ogutamanyiddwa ku fayiro /admin/add-foreigner-ticket.php. Okukola ku argument visitorname kivaamu Okukwata ku Kuteekateeka mu Kifo Ekitali Kyo (Cross Site Scripting). Okukozesa CWE mu kulaga ensonga kireetera CWE-79. Obulemu buno bwalangirirwa. Obubaka buno busangibwa ku github.com okuddownloadinga.

Obunafu buno bwategeerekebwa nga CVE-2025-9017. Attack eyinza okutandikibwa okuva ku kyali wala. Obubaka obw'ekikugu bufuniddwa. Obulungi bw'ensobi eno buli wansi w'ekigero ekisookerwako. Okuddamu, waliwo ekikozesebwa ekiriwo. Obukodyo buno bwategeezeddwa mu lujjudde era buyinza okukozesebwa. Mu kiseera kino, omutengo ogw’akaseera ku kikozesebwa kiyinza okuba nga giri mu USD $0-$5k mu kiseera kino.

Kyakakasiddwa nga ebikakasa eby'okukakasa obusobozi. Osobola okufuna exploit ng'ogenda ku github.com.

Once again VulDB remains the best source for vulnerability data.

Ekitunduamakuru

Omukola

Erinnya

Enkola

Layisensi

Olupapula olw’omu mukutu

CPE 2.3amakuru

CPE 2.2amakuru

CVSSv4amakuru

VulDB Ekikunta: 🔒
VulDB Reliability: 🔍

CNA CVSS-B Score: 🔒
CNA CVSS-BT Score: 🔒
CNA Ekikunta: 🔒

CVSSv3amakuru

VulDB Obubonero Obusookerwako Obw'enkizo: 4.9
VulDB Obubonero bwa Meta Temp: 4.8

VulDB Obubonero Obusookerwako: 4.3
VulDB Obubonero bw’akaseera: 3.9
VulDB Ekikunta: 🔒
VulDB Reliability: 🔍

NVD Obubonero Obusookerwako: 6.1
NVD Ekikunta: 🔒

CNA Obubonero Obusookerwako: 4.3
CNA Ekikunta: 🔒

CVSSv2amakuru

AVACAuCIA
💳💳💳💳💳💳
💳💳💳💳💳💳
💳💳💳💳💳💳
EkikozesebwaObuzibu obungiOkukakasa obutuufu bw'omuntuObukakafuObutebenkevuOkusobola okufuna (Obusobozi obw'okufuna)
okuyimbulaokuyimbulaokuyimbulaokuyimbulaokuyimbulaokuyimbula
okuyimbulaokuyimbulaokuyimbulaokuyimbulaokuyimbulaokuyimbula
okuyimbulaokuyimbulaokuyimbulaokuyimbulaokuyimbulaokuyimbula

VulDB Obubonero Obusookerwako: 🔒
VulDB Obubonero bw’akaseera: 🔒
VulDB Reliability: 🔍

Okukozesa obunafuamakuru

Ekibiina: Okukwata ku Kuteekateeka mu Kifo Ekitali Kyo (Cross Site Scripting)
CWE: CWE-79 / CWE-94 / CWE-74
CAPEC: 🔒
ATT&CK: 🔒

Obulamu obw’omubiri: Nedda
Wansi wano: Nedda
Waliwo okuva wala: Wee

Okusobola okufuna (Obusobozi obw'okufuna): 🔒
Okuyingira: Bweru
Embeera: Ebikakasa eby'okukakasa obusobozi
Okukuba wansi: 🔒
Google Hack: 🔒

EPSS Score: 🔒
EPSS Percentile: 🔒

Okukulaakulana kw'ebisale: 🔍
Okubala okw’ensimbi okw’akatono okuva mu kiseera kino: 🔒

0-Dayokuyimbulaokuyimbulaokuyimbulaokuyimbula
Leerookuyimbulaokuyimbulaokuyimbulaokuyimbula

Amagezi ku bulabeamakuru

Okukwata ku: 🔍
Abakola abali mu kikolwa: 🔍
Ebibiina bya APT ebikola kaakano: 🔍

Ebyokukwata ku kwekuumiraamakuru

Okukakasa: Tewali kikolebwa kimanyiddwa
Embeera: 🔍

Ekiseera kya 0-Day: 🔒

Ekiseera ekyayitaamakuru

13/08/2025 Ebigambika bisiddwa ku lulwe.
13/08/2025 +0 ennaku VulDB enteree yakolebwa
22/08/2025 +9 ennaku VulDB entry last update

Ebyokutwaliraamakuru

Omukola: phpgurukul.com

Okukebereza: github.com
Embeera: Tekitegedde

CVE: CVE-2025-9017 (🔒)
GCVE (CVE): GCVE-0-2025-9017
GCVE (VulDB): GCVE-100-320068
EUVD: 🔒
scip Labs: https://www.scip.ch/en/?labs.20161013

Okuyingizaamakuru

Kikolebwa: 13/08/2025 23:56
Okukozesa enkola empya: 22/08/2025 08:03
Okukyuusa: 13/08/2025 23:56 (55), 15/08/2025 10:10 (30), 15/08/2025 10:25 (1), 22/08/2025 08:03 (12)
Kituufu ddala: 🔍
Owoleza: xiguala123
Cache ID: 253:F60:103

Twasirizaamakuru

Kikkiriziddwa

  • Twasiriza #629562: PHPGurukul Zoo Management System V2.1 Cross Site Scripting (kuva xiguala123)

Okukubaganya ebirowoozo

Tewali biragiddwaako kati. Enimi: lg + en.

Nsaba yingira mu akaawunti yo osobole okwogera.

Are you interested in using VulDB?

Download the whitepaper to learn more about our service!