PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) in the worksheet.php file via the participant_name parameter.
References
| Link | Resource |
|---|---|
| https://gold-textbook-8ff.notion.site/php-education-management-Stored-XSS-Vulnerability-25985e97f35380018b9af0f4b678002c?pvs=73 | Exploit Third Party Advisory |
Configurations
History
22 Oct 2025, 16:52
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://gold-textbook-8ff.notion.site/php-education-management-Stored-XSS-Vulnerability-25985e97f35380018b9af0f4b678002c?pvs=73 - Exploit, Third Party Advisory | |
| First Time |
Iqbolshoh
Iqbolshoh php Education Management |
|
| CPE | cpe:2.3:a:iqbolshoh:php_education_management:1.0:*:*:*:*:*:*:* |
20 Oct 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-20 21:15
Updated : 2025-10-22 16:52
NVD link : CVE-2025-60781
Mitre link : CVE-2025-60781
CVE.ORG link : CVE-2025-60781
JSON object : View
Products Affected
iqbolshoh
- php_education_management
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
