---
id: CVE-2025-15406
title: A flaw has been found in PHPGurukul Online Course Registration up to 3.1
summary: >-
  A flaw has been found in PHPGurukul Online Course Registration up to 3.1. This
  affects an unknown function. This manipulation causes missing authorization.
  Remote exploitation of the attack is possible. The exploit has been published
  and…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-862
  - CWE-863
vendor: phpgurukul
product: online_course_registration
affected:
  - online_course_registration <= 3.1
published: '2026-01-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T08:10:00.183'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15406'
references:
  - url: >-
      https://github.com/rsecroot/Online-Course-Registration/blob/main/Broken%20Access%20Control.md
    label: cna@vuldb.com
  - url: 'https://phpgurukul.com/'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.339326'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.339326'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.728354'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00455
epssPercentile: 0.37014
ingestedAt: '2026-10-01T08:40:11.720Z'
---

## Overview

A flaw has been found in PHPGurukul Online Course Registration up to 3.1. This affects an unknown function. This manipulation causes missing authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used.

## Affected

- `online_course_registration <= 3.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
