CVE-2025-13577: PHPGurukul Hostel Management System register-complaint.php cross site scripting
A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the file /register-complaint.php. Executing a manipulation of the argument cdetails can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13577?
CVE-2025-13577 has a high severity rating due to its potential for remote cross-site scripting attacks.
How do I fix CVE-2025-13577?
To fix CVE-2025-13577, sanitize and validate all user inputs in the '/register-complaint.php' file to prevent XSS attacks.
What impacts does CVE-2025-13577 have on my application?
CVE-2025-13577 can allow attackers to execute malicious scripts in the context of users' browsers, potentially compromising user data.
Can CVE-2025-13577 be exploited remotely?
Yes, CVE-2025-13577 can be exploited remotely since it involves a public-facing component of the PHPGurukul Hostel Management System.
Which version of PHPGurukul Hostel Management System is affected by CVE-2025-13577?
CVE-2025-13577 affects PHPGurukul Hostel Management System version 2.1.