CVE-2025-70899: Phpgurukul Online Course Registration

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative forms. An attacker can perform unauthorized actions on behalf of authenticated administrators by tricking them into visiting a malicious webpage.

Affected products

  • Phpgurukul Online Course Registration: version 3.1 only

Published 2026-01-22. Last modified 2026-06-17.