PT-2025-40396 · Unknown · Php Education Manager

Published

2025-10-02

·

Updated

2025-10-02

·

CVE-2025-60782

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHP Education Manager version 1.0
Description The software contains a Cross-Site Scripting (XSS) issue within the topics management module, specifically in the topics.php file. An attacker can inject malicious JavaScript payloads into the Title field when creating or updating topics. This allows for the execution of arbitrary JavaScript code within the context of other users' browsers.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-60782

Affected Products

Php Education Manager