---
id: CVE-2025-11119
title: >-
  A security flaw has been discovered in itsourcecode Hostel Management System
  1.0
summary: >-
  A security flaw has been discovered in itsourcecode Hostel Management System
  1.0. Impacted is an unknown function of the file /justines/index.php of the
  component POST Request Handler. Performing manipulation of the argument from
  results…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: angeljudesuarez
product: hostel_management_system
affected:
  - hostel_management_system = 1.0
published: '2025-09-28'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T09:10:00.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11119'
references:
  - url: 'https://github.com/iflame28/CVE/issues/1'
    label: cna@vuldb.com
  - url: 'https://itsourcecode.com/'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.326200'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.326200'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.663519'
    label: cna@vuldb.com
  - url: 'https://github.com/iflame28/CVE/issues/1'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00395
epssPercentile: 0.31563
ingestedAt: '2026-10-09T09:31:00.974Z'
---

## Overview

A security flaw has been discovered in itsourcecode Hostel Management System 1.0. Impacted is an unknown function of the file /justines/index.php of the component POST Request Handler. Performing manipulation of the argument from results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.

## Affected

- `hostel_management_system = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
