CVE-2025-11112 MEDIUM

CVE-2025-11112: PHPGurukul Employee Record Management System myprofile.php cross site scripting

Vendor Phpgurukul
Product Employee Record Management System
Weakness CWE-79 · XSS
Published September 28, 2025
Last update September 29, 2025

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A security vulnerability has been detected in PHPGurukul Employee Record Management System 1.3. This impacts an unknown function of the file /myprofile.php. Such manipulation of the argument First name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.

Key dates

02Disclosure timeline

September 28, 2025 CVE published
September 29, 2025 Record updated