ZeroHour

CVE-2025-60782

PoC ×2
CVSS 3.1
5.4 medium
EPSS
<1%p13
Published
()
Modified
Description

PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) stored Cross-Site Scripting (XSS) vulnerability in the topics management module (topics.php). Attackers can inject malicious JavaScript payloads into the Titlefield during topic creation or updates.

Vendors
iqbolshoh
Products
php education management
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.