Impact
The flaw resides in the /admin/manage-students.php file of PHPGurukul Hostel Management System version 3.0. It allows a remote attacker to inject and execute arbitrary JavaScript within a page served to administrators. This injection aligns with CWE‑79 for cross‑site scripting and CWE‑94 for code injection. The vulnerability is triggered when user‑supplied data reaches the output stream without proper sanitization, enabling the attacker to run malicious scripts in the victim’s browser.
Affected Systems
The only documented impact is on PHPGurukul Hostel Management System 3.0. No other versions or related products are listed as affected. The vulnerability is tied specifically to the manage‑students module under the admin interface.
Risk and Exploitability
The CVSS score of 4.8 reflects a moderate severity for client‑side impact. EPSS is reported as < 1 %, indicating a very low likelihood of widespread exploitation, although the exploit code is publicly available. The attack can be launched remotely through crafted requests to the manage‑students endpoint and does not compromise server data directly. The vulnerability is not listed in the CISA KEV catalog, which suggests it has not yet been observed in a large‑scale exploitation campaign.
OpenCVE Enrichment