CVE-2026-90850: PHPGurukul Hostel Management System manage-students.php cross site scripting
A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionality of the file /admin/manage-students.php. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What level of access and interaction are needed to exploit this issue?
The supplied CVSS vector indicates an attacker needs high privileges and user interaction. The attack can be launched remotely, but exploitation requires a privileged attacker to cause a user to interact with the crafted content.
Is there evidence that exploitation is practical?
Yes. A public exploit is reported to be available, which may make exploitation easier for attackers with the required privileges.
What is the known impact if exploitation succeeds?
The reported impact is limited to integrity, with no reported confidentiality or availability impact. The vulnerability is classified as cross-site scripting in /admin/manage-students.php.