Impact
The flaw resides in the admin/manage‑students.php file of PHPGurukul Hostel Management System version 3.0, where malicious input can bypass input validation and inject arbitrary JavaScript into the rendered page. This cross‑site scripting allows a remote attacker to run code in the victim’s browser, which could be used for session hijacking, defacement, or malicious redirects. The issue is explicitly identified as CWE‑79 and involves code injection behavior (CWE‑94).
Affected Systems
Affected software is PHPGurukul Hostel Management System 3.0, specifically the administrative manage‑students functionality. No other products or versions were listed as impacted.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate risk, and the exploit is publicly available,ible. EPSS data is unavailable and the vulnerability is not catalogued in CISA’s KEV list, but the public nature of the exploit increases the practical risk. Attackers can remotely trigger the issue via a crafted URL or form submission to the manage‑students page. Given the client‑side impact, the threat to confidentiality, integrity, and availability is limited to the affected user session.
OpenCVE Enrichment