---
id: CVE-2025-11390
title: A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0
summary: >-
  A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0.
  Affected by this vulnerability is an unknown functionality of the file
  /search.php of the component POST Parameter Handler. Executing a manipulation
  of the ar…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
  - CWE-79
vendor: phpgurukul
product: cyber_cafe_management_system
affected:
  - cyber_cafe_management_system = 1.0
published: '2025-10-07'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:10:00.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11390'
references:
  - url: 'https://github.com/QIU-DIE/CVE/issues/4'
    label: cna@vuldb.com
  - url: 'https://phpgurukul.com/'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.327317'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327317'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.664984'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.665028'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00359
epssPercentile: 0.27559
ingestedAt: '2026-10-08T22:11:53.790Z'
---

## Overview

A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /search.php of the component POST Parameter Handler. Executing a manipulation of the argument searchdata can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

## Affected

- `cyber_cafe_management_system = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
