School Management System PHP v1.0 is vulnerable to Cross Site Scripting (XSS) in /login.php via the password parameter.
References
| Link | Resource |
|---|---|
| https://github.com/sanin-s1r3n/CVE-Research/blob/main/CVE-6 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
03 Feb 2026, 15:01
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
School Management System Php Project
School Management System Php Project school Management System Php |
|
| References | () https://github.com/sanin-s1r3n/CVE-Research/blob/main/CVE-6 - Exploit, Third Party Advisory | |
| CPE | cpe:2.3:a:school_management_system_php_project:school_management_system_php:1.0:*:*:*:*:*:*:* |
Information
Published : 2025-11-03 15:15
Updated : 2026-02-03 15:01
NVD link : CVE-2025-63443
Mitre link : CVE-2025-63443
CVE.ORG link : CVE-2025-63443
JSON object : View
Products Affected
school_management_system_php_project
- school_management_system_php
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
