PT-2025-37117 · Undefined · Undefined
Published
2025-09-11
·
Updated
2026-02-26
·
CVE-2025-56605
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PuneethReddyHC Event Management System version 1.0
Description
A reflected Cross-Site Scripting (XSS) issue exists in the
register.php script. The mobile parameter is not properly validated, and its value is echoed in the HTTP response without sanitization. This allows an attacker to inject and execute arbitrary JavaScript code in a victim’s browser. The vulnerable parameter is mobile.Recommendations
Ensure proper validation and sanitization of the
mobile parameter in the register.php script to prevent the injection of malicious JavaScript code.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined