CVE-2025-11119
⚪ Do wiadomości
Wstrzyknięcie skryptów w Hostel Management System umożliwia zdalne ataki XSS.
CVSS
4.3
EPSS
0.4%
Exploit
poc
Vendor
angeljudesuarez
Opis źródłowy (NVD)
A security flaw has been discovered in itsourcecode Hostel Management System 1.0. Impacted is an unknown function of the file /justines/index.php of the component POST Request Handler. Performing manipulation of the argument from results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.
exploit xss
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 4.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2025-09-28 21:15:50 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-09 09:10:00 UTC |
Referencje
- https://github.com/iflame28/CVE/issues/1 ([email protected]) [Exploit, Third Party Advisory]
- https://itsourcecode.com/ ([email protected]) [Product]
- https://vuldb.com/?ctiid.326200 ([email protected]) [Permissions Required, VDB Entry]
- https://vuldb.com/?id.326200 ([email protected]) [Third Party Advisory, VDB Entry]
- https://vuldb.com/?submit.663519 ([email protected]) [Third Party Advisory, VDB Entry]