A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this issue is some unknown functionality of the file /registration.php. Executing manipulation of the argument Username can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/YoSheep/cve/blob/main/PHPGurukul%20Small%20CRM%20in%20PHP%20V4.0%20Multiple%20Stored%20Cross-Site%20Scripting%20(XSS)%20Vulnerabilities.md | Exploit Third Party Advisory |
| https://phpgurukul.com/ | Product |
| https://vuldb.com/?ctiid.322181 | Permissions Required VDB Entry |
| https://vuldb.com/?id.322181 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.642025 | Third Party Advisory VDB Entry |
| https://github.com/YoSheep/cve/blob/main/PHPGurukul%20Small%20CRM%20in%20PHP%20V4.0%20Multiple%20Stored%20Cross-Site%20Scripting%20(XSS)%20Vulnerabilities.md | Exploit Third Party Advisory |
Configurations
History
05 Sep 2025, 17:46
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/YoSheep/cve/blob/main/PHPGurukul%20Small%20CRM%20in%20PHP%20V4.0%20Multiple%20Stored%20Cross-Site%20Scripting%20(XSS)%20Vulnerabilities.md - Exploit, Third Party Advisory | |
| References | () https://phpgurukul.com/ - Product | |
| References | () https://vuldb.com/?ctiid.322181 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.322181 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.642025 - Third Party Advisory, VDB Entry | |
| CPE | cpe:2.3:a:phpgurukul:small_crm:4.0:*:*:*:*:*:*:* | |
| First Time |
Phpgurukul
Phpgurukul small Crm |
03 Sep 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/YoSheep/cve/blob/main/PHPGurukul%20Small%20CRM%20in%20PHP%20V4.0%20Multiple%20Stored%20Cross-Site%20Scripting%20(XSS)%20Vulnerabilities.md - |
02 Sep 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-02 21:15
Updated : 2025-09-05 17:46
NVD link : CVE-2025-9834
Mitre link : CVE-2025-9834
CVE.ORG link : CVE-2025-9834
JSON object : View
Products Affected
phpgurukul
- small_crm
