CVE-2025-11390: PHPGurukul Cyber Cafe Management System POST Parameter search.php cross site scripting
A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /search.php of the component POST Parameter Handler. Executing a manipulation of the argument searchdata can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11390?
The severity of CVE-2025-11390 has not been explicitly rated, but it involves a cross-site scripting vulnerability that can potentially compromise users' data.
How do I fix CVE-2025-11390?
To fix CVE-2025-11390, ensure to validate and sanitize the input for the searchdata parameter in the /search.php file.
What systems are affected by CVE-2025-11390?
CVE-2025-11390 specifically affects version 1.0 of the PHPGurukul Cyber Cafe Management System.
What type of vulnerability is CVE-2025-11390?
CVE-2025-11390 is classified as a cross-site scripting (XSS) vulnerability.
Can CVE-2025-11390 be exploited remotely?
Yes, CVE-2025-11390 can be exploited remotely by manipulating the searchdata parameter in the affected application.