Filtered by vendor Phpgurukul Subscriptions
Filtered by product Cybercafe Management System Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-70890 1 Phpgurukul 1 Cybercafe Management System 2026-01-16 6.1 Medium
A stored cross-site scripting (XSS) vulnerability exists in Cyber Cafe Management System v1.0. An authenticated attacker can inject arbitrary JavaScript code into the username parameter via the add-users.php endpoint. The injected payload is stored and executed in the victim s browser when the affected page is accessed.