CVE-2025-12303: PHPGurukul Curfew e-Pass Management System admin-profile.php cross site scripting
A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. The impacted element is an unknown function of the file admin-profile.php. Executing a manipulation of the argument adminname/email can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12303?
CVE-2025-12303 has a high severity due to its potential for cross-site scripting attacks.
How do I fix CVE-2025-12303?
To fix CVE-2025-12303, sanitize all user inputs for the adminname and email parameters in the admin-profile.php file.
What software is affected by CVE-2025-12303?
CVE-2025-12303 affects PHPGurukul Curfew e-Pass Management System version 1.0.
How can CVE-2025-12303 be exploited?
CVE-2025-12303 can be exploited remotely through manipulation of the adminname or email parameter in a web request.
What impact does CVE-2025-12303 have on users?
CVE-2025-12303 can lead to unauthorized script execution in a user's browser, potentially compromising user information.