PHPGurukul Rail Pass Management System

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in PHPGurukul Rail Pass Management System.

By the Year

In 2026 there have been 0 vulnerabilities in PHPGurukul Rail Pass Management System. Last year, in 2025 Rail Pass Management System had 8 security vulnerabilities published. Right now, Rail Pass Management System is on track to have less security vulnerabilities in 2026 than it did last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 8 7.25
2024 0 0.00
2023 7 6.89

It may take a day or so for new Rail Pass Management System vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent PHPGurukul Rail Pass Management System Security Vulnerabilities

PHPGurukul Rail Pass MS 1.0 XSS via /contact.php Name
CVE-2025-6126 5.4 - Medium - June 16, 2025

A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /contact.php. The manipulation of the argument Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

XSS

CVE-2025-6125: XSS via pagedes in PHPGurukul Rail Pass System 1.0
CVE-2025-6125 5.4 - Medium - June 16, 2025

A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/aboutus.php. The manipulation of the argument pagedes leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

XSS

PHPGurukul Rail Pass System 1.0 XSS via fullname in /admin/add-pass.php
CVE-2025-5976 5.4 - Medium - June 10, 2025

A vulnerability has been found in PHPGurukul Rail Pass Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/add-pass.php. The manipulation of the argument fullname leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

XSS

PHPGurukul Rail Pass Mngmt 1.0 XSS via /download-pass.php searchdata
CVE-2025-5975 6.1 - Medium - June 10, 2025

A vulnerability, which was classified as problematic, was found in PHPGurukul Rail Pass Management System 1.0. This affects an unknown part of the file /rpms/download-pass.php. The manipulation of the argument searchdata leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

XSS

SQLi via /admin/pass-bwdates-reports-details.php in PHPGurukul Rail Pass Mgmt 1.0
CVE-2025-5554 8.8 - High - June 04, 2025

A vulnerability, which was classified as critical, has been found in PHPGurukul Rail Pass Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/pass-bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

PHPGurukul Rail Pass Management System 1.0 Remote SQLi via /download-pass.php
CVE-2025-5553 7.3 - High - June 04, 2025

A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /download-pass.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

SQLi via editid in PHPGurukul Rail Pass Management 1.0 /admin/changeimage.php
CVE-2025-4070 9.8 - Critical - April 29, 2025

A vulnerability, which was classified as critical, was found in PHPGurukul Rail Pass Management System 1.0. This affects an unknown part of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

PHPGurukul Rail Pass 1.0: SQLI via /admin/search-pass.php
CVE-2025-4039 9.8 - Critical - April 28, 2025

A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/search-pass.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

SQLi in Rail Pass Management System v1.0 edit-cateogry-detail.php (editid)
CVE-2023-31937 7.2 - High - July 28, 2023

Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-cateogry-detail.php file.

SQL Injection

Rail Pass Mgmt Sys 1.0 SQLi via viewid param in view-pass-detail.php
CVE-2023-31936 7.2 - High - July 28, 2023

Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the viewid parameter of the view-pass-detail.php file.

SQL Injection

Rail Pass Management System v1.0 - XSS in admin-profile.php via emial parameter
CVE-2023-31935 4.8 - Medium - July 28, 2023

Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the emial parameter of admin-profile.php.

XSS

CVE-2023-31934 XSS in Rail Pass Management System v1.0 (adminname)
CVE-2023-31934 4.8 - Medium - July 28, 2023

Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the adminname parameter of admin-profile.php.

XSS

Rail Pass MS v1.0 Remote SQLi via editid in edit-pass-detail.php
CVE-2023-31933 7.2 - High - July 28, 2023

Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-pass-detail.php file.

SQL Injection

Rail Pass Mgmt Sys 1.0: Remote SQLi via viewid (view-enquiry.php)
CVE-2023-31932 7.2 - High - July 28, 2023

Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the viewid parameter of the view-enquiry.php file.

SQL Injection

Critical SQLi in PHPGurukul Rail Pass MT 1.0 via POST searchdata
CVE-2023-3275 9.8 - Critical - June 15, 2023

A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view-pass-detail.php of the component POST Request Handler. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The identifier VDB-231625 was assigned to this vulnerability.

SQL Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for PHPGurukul Rail Pass Management System or by PHPGurukul? Click the Watch button to subscribe.

 

PHPGurukul
Vendor

subscribe