Vulnerability Description
Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint) submitted via /register-complaint.php are stored and rendered unescaped in the admin viewer (/admin/complaint-details.php?cid=<id>). When an administrator opens the complaint, injected HTML/JavaScript executes in the admin's browser.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpgurukul | Hostel Management System | 2.1 |
Related Weaknesses (CWE)
References
- https://medium.com/@tanushkushtk01/cve-2025-63611-stored-cross-site-scripting-xsExploitThird Party Advisory
- https://phpgurukul.com/hostel-management-system/Product
FAQ
What is CVE-2025-63611?
CVE-2025-63611 is a vulnerability with a CVSS score of 8.7 (HIGH). Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint) submitted via /register-complaint.php are stored and rendered unescaped in the a...
How severe is CVE-2025-63611?
CVE-2025-63611 has been rated HIGH with a CVSS base score of 8.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-63611?
Check the references section above for vendor advisories and patch information. Affected products include: Phpgurukul Hostel Management System.