High severity8.7NVD Advisory· Published Jan 8, 2026· Updated Jun 17, 2026
CVE-2025-63611
CVE-2025-63611
Description
Cross-Site Scripting in phpgurukul Hostel Management System v2.1 user-provided complaint fields (Explain the Complaint) submitted via /register-complaint.php are stored and rendered unescaped in the admin viewer (/admin/complaint-details.php?cid=). When an administrator opens the complaint, injected HTML/JavaScript executes in the admin's browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:phpgurukul:hostel_management_system:2.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:phpgurukul:hostel_management_system:2.1:*:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: = 2.1
Patches
Vulnerability mechanics
References
2- medium.com/@tanushkushtk01/cve-2025-63611-stored-cross-site-scripting-xss-in-hostel-management-system-v2-1-a23c2efc86eanvdExploitThird Party Advisory
- phpgurukul.com/hostel-management-system/nvdProduct
News mentions
0No linked articles in our index yet.