CVE-2025-63955: Phpgurukul Student Record System
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record System v3.2 allows an attacker to trick an authenticated administrator into submitting a forged request. This leads to the unauthorized deletion of user accounts, causing a Denial of Service (DoS).
Affected products
- Phpgurukul Student Record System: version 3.2 only
Published 2025-11-18. Last modified 2026-06-17.