CVE 8.7 HIGH

CVE-2025-63611_CVE-2025-63611

8.7 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Description

Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint) submitted via /register-complaint.php are stored and rendered unescaped in the admin viewer (/admin/complaint-details.php?cid=<id>). When an administrator opens the complaint, injected HTML/JavaScript executes in the admin's browser.

AI Analysis

Stored Cross-Site Scripting (XSS) vulnerability in phpgurukul Hostel Management System

Basic Information

ID CVE-2025-63611
Source mitre
Published Jan 8, 2026 at 00:00
Modified Jan 8, 2026 at 16:37

Affected Product

Vendor phpgurukul
Product phpgurukul Hostel Management System
Version v2.1
Affected Versions n/a n/a n/a

CWE Classification

AI Assessment

AI Score 8.7 / 10
AI Severity High
Vendor phpgurukul
Product Hostel Management System
Version v2.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.