PT-2025-42923 · Phpgurukul · Bank Locker Management System

Published

2025-10-21

·

Updated

2025-10-21

·

CVE-2025-61255

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bank Locker Management System by PHPGurukul (affected versions not specified)
Description The Bank Locker Management System is susceptible to a Cross-Site Scripting (XSS) issue. The /search parameter does not properly sanitize input, allowing the injection of arbitrary HTML and JavaScript code. Successful exploitation could lead to information disclosure and user redirection.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-61255

Affected Products

Bank Locker Management System