A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /registration.php. Executing manipulation of the argument Username can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/YoSheep/cve/blob/main/PHPGurukul%20Small%20CRM%20in%20PHP%20V4.0%20Multiple%20Stored%20Cross-Site%20Scripting%20(XSS)%20Vulnerabilities.md | Exploit Third Party Advisory |
| https://phpgurukul.com/ | Product |
| https://vuldb.com/?ctiid.322181 | Permissions Required VDB Entry |
| https://vuldb.com/?id.322181 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.642025 | Third Party Advisory VDB Entry |
| https://github.com/YoSheep/cve/blob/main/PHPGurukul%20Small%20CRM%20in%20PHP%20V4.0%20Multiple%20Stored%20Cross-Site%20Scripting%20(XSS)%20Vulnerabilities.md | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-09-02 21:15
Updated : 2025-09-05 17:46
NVD link : CVE-2025-9834
Mitre link : CVE-2025-9834
CVE.ORG link : CVE-2025-9834
JSON object : View
Products Affected
phpgurukul
- small_crm
