CVE-2024-51225: Phpgurukul Vehicle Record Management System

Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A stored cross-site scripting (XSS) vulnerability in the component /admin/add-brand.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the brandname parameter.

Affected products

  • Phpgurukul Vehicle Record Management System: version 1.0 only

Published 2026-03-23. Last modified 2026-06-17.