CVE-2025-13577Low· 3.5▾ SunlitA flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the file /register-complaint.php. Executing a manipulation of the argument cdetails can lead to cross site scripting. It is …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 19.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the file /register-complaint.php. Executing a manipulation of the argument cdetails can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.
hostel_management_system = 2.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-12312Low· 2.4A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0
CVE-2025-12311Low· 2.4A vulnerability was detected in PHPGurukul Curfew e-Pass Management System 1.0
CVE-2025-12303Low· 2.4A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0
CVE-2026-90850Low· 2.4A vulnerability was detected in PHPGurukul Hostel Management System 3.0
CVE-2026-90845Low· 3.5A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1
CVE-2022-35155Medium· 6.1Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter.