CVE-2025-11390 PUBLISHED

PHPGurukul Cyber Cafe Management System POST Parameter search.php cross site scripting

Assigner: VulDB
Reserved: 06.10.2025 Published: 07.10.2025 Updated: 07.10.2025

A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /search.php of the component POST Parameter Handler. Executing manipulation of the argument searchdata can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor PHPGurukul
Product Cyber Cafe Management System
Versions
  • Version 1.0 is affected

Credits

  • hhsw34 (VulDB User) reporter

References

Problem Types

  • Cross Site Scripting CWE
  • Code Injection CWE