What is CVE-2026-19207?
A Cross Site Scripting (XSS) vulnerability has been identified in PHPGurukul Company Visitor Management System 1.0, affecting the "manage-newvisitors.php" file. Remote attackers can manipulate the "fullname" argument to inject and execute malicious scripts in users' browsers. It is recommended to immediately patch or update the affected system.
Azərbaycanca: PHPGurukul Şirkət Ziyarətçi İdarəetmə Sistemi 1.0 versiyasında "manage-newvisitors.php" faylında Cross Site Scripting (XSS) zəifliyi aşkar edilib. Bu, uzaqdan hücum edənə "fullname" parametrini manipulyasiya edərək istifadəçilərin brauzerində zərərli skript icra etməyə imkan verə bilər. Təhlükəsizlik üçün dərhal sisteminizi yeniləməyiniz tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which version of PHPGurukul Company Visitor Management System is affected by the CVE-2026-19207 XSS vulnerability?
Version 1.0 of the PHPGurukul Company Visitor Management System is affected by this vulnerability.
Which parameter can an attacker manipulate to carry out the XSS attack in CVE-2026-19207?
An attacker can manipulate the 'fullname' parameter in the 'manage-newvisitors.php' file to carry out the XSS attack.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.