CVE-2025-11119

⚪ Do wiadomości

Wstrzyknięcie skryptów w Hostel Management System umożliwia zdalne ataki XSS.

CVSS
4.3
EPSS
0.4%
Exploit
poc
Vendor
angeljudesuarez
Opis źródłowy (NVD)

A security flaw has been discovered in itsourcecode Hostel Management System 1.0. Impacted is an unknown function of the file /justines/index.php of the component POST Request Handler. Performing manipulation of the argument from results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.

exploit xss Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS4.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2025-09-28 21:15:50 UTC
Ostatnia modyfikacja (NVD)2026-10-09 09:10:00 UTC
Referencje