CVE-2025-12311: PHPGurukul Curfew e-Pass Management System edit-category-detail.php cross site scripting
A vulnerability was detected in PHPGurukul Curfew e-Pass Management System 1.0. This issue affects some unknown processing of the file edit-category-detail.php. The manipulation of the argument catname results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12311?
CVE-2025-12311 is classified as a cross-site scripting (XSS) vulnerability, which can have a significant impact if exploited.
How do I fix CVE-2025-12311?
To fix CVE-2025-12311, ensure proper input validation and output encoding for the catname parameter in the edit-category-detail.php file.
What types of attacks can be executed using CVE-2025-12311?
Exploiting CVE-2025-12311 can lead to remote cross-site scripting attacks, allowing attackers to execute malicious scripts in a user's browser.
Which software versions are affected by CVE-2025-12311?
CVE-2025-12311 affects version 1.0 of the PHPGurukul Curfew e-Pass Management System.
Is remote exploitation possible with CVE-2025-12311?
Yes, CVE-2025-12311 can be exploited remotely, making it a critical concern for cybersecurity.