Cross Site Scripting Vulnerability in School Management System PHP by Sanin S1r3n
CVE-2025-63443 
5.4MEDIUM
What is CVE-2025-63443?
The School Management System PHP v1.0 has a Cross Site Scripting (XSS) vulnerability located in the login functionality. An attacker can exploit this through the password parameter in /login.php, potentially leading to unauthorized actions and access to sensitive user data. Proper sanitization of user input and implementation of security measures are essential to mitigate this risk.
