A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
History

Tue, 17 Jun 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Phpgurukul
Phpgurukul restaurant Table Booking System
CPEs cpe:2.3:a:phpgurukul:restaurant_table_booking_system:1.0:*:*:*:*:*:*:*
Vendors & Products Phpgurukul
Phpgurukul restaurant Table Booking System

Tue, 10 Jun 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php. The manipulation of the argument fullname leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Title PHPGurukul Restaurant Table Booking System add-subadmin.php cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 3.3, 'vector': 'AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 2.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-06-10T17:00:10.161Z

Updated: 2025-06-10T17:31:23.407Z

Reserved: 2025-06-10T11:24:17.376Z

Link: CVE-2025-5970

cve-icon Vulnrichment

Updated: 2025-06-10T17:30:51.820Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-10T17:25:24.033

Modified: 2025-06-17T20:35:26.663

Link: CVE-2025-5970

cve-icon Redhat

No data.