Description
A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionality of the file /admin/manage-students.php. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.
Published: 2026-09-15
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑site scripting that allows remote execution of arbitrary client‑side code
Action: Apply Patch
AI Analysis

Impact

The flaw resides in the /admin/manage-students.php file of PHPGurukul Hostel Management System version 3.0. It allows a remote attacker to inject and execute arbitrary JavaScript within a page served to administrators. This injection aligns with CWE‑79 for cross‑site scripting and CWE‑94 for code injection. The vulnerability is triggered when user‑supplied data reaches the output stream without proper sanitization, enabling the attacker to run malicious scripts in the victim’s browser.

Affected Systems

The only documented impact is on PHPGurukul Hostel Management System 3.0. No other versions or related products are listed as affected. The vulnerability is tied specifically to the manage‑students module under the admin interface.

Risk and Exploitability

The CVSS score of 4.8 reflects a moderate severity for client‑side impact. EPSS is reported as < 1 %, indicating a very low likelihood of widespread exploitation, although the exploit code is publicly available. The attack can be launched remotely through crafted requests to the manage‑students endpoint and does not compromise server data directly. The vulnerability is not listed in the CISA KEV catalog, which suggests it has not yet been observed in a large‑scale exploitation campaign.

Generated by OpenCVE AI on September 17, 2026 at 18:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor release that fixes the XSS issue in /admin/manage-students.php as soon as it becomes available.
  • If a patch is not yet released, modify the page to encode or escape all user‑supplied data before rendering, e.g., by using htmlspecialchars() or a similar function.
  • Deploy a content security policy that blocks inline scripts and restricts script sources to mitigate the impact of any remaining cross‑site scripting.

Generated by OpenCVE AI on September 17, 2026 at 18:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionality of the file /admin/manage-students.php. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used.
Title PHPGurukul Hostel Management System manage-students.php cross site scripting
First Time appeared Phpgurukul
Phpgurukul hostel Management System
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:phpgurukul:hostel_management_system:*:*:*:*:*:*:*:*
Vendors & Products Phpgurukul
Phpgurukul hostel Management System
References
Metrics cvssV2_0

{'score': 3.3, 'vector': 'AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 2.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Phpgurukul Hostel Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:54:21.086Z

Reserved: 2026-09-14T05:30:25.349Z

Link: CVE-2026-90850

cve-icon Vulnrichment

Updated: 2026-09-15T13:42:02.136Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T02:16:49.143

Modified: 2026-09-15T14:37:14.523

Link: CVE-2026-90850

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')