PHPGurukul Art Gallery Management System Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in PHPGurukul Art Gallery Management System version 1.0. The issue resides in the search.php file, where the search parameter is not properly sanitized, allowing attackers to inject malicious scripts. This vulnerability can be exploited remotely, potentially executing harmful scripts in the context of the user's browser.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where injected scripts are executed in the user's browser session.

Reproduction

To reproduce this vulnerability, navigate to the search.php page of the Art Gallery Management System. In the 'Search' input box, enter a script payload, such as a script tag containing JavaScript code, such as an alert. After submitting the search, the injected script will execute, demonstrating the cross-site scripting vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
1.7
exploitability
7.9
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.