
Proof-of-concept for a reflected XSS vulnerability in Event Management System 1.0, demonstrating improper input validation in register.php and providing mitigation guidance.
XSS (Cross-Site Scripting Vulnerability)
Description:
A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC/event-management 1.0.
The mobile POST parameter is improperly validated and reflected back in the response, allowing injection of arbitrary JavaScript code.
CVE ID: CVE-2025-56605
Discovered by: Isroil Mustafoqulov
Vulnerability type: Reflected XSS
Attack vector: Remote
Steps to reproduce (local only):
backend/register.php with a malicious payload in the mobile parameter.⚠️ Payloads are intentionally omitted. Do not attempt exploitation on systems you do not own.
Sanitize/encode user input before output. Example in PHP:
echo htmlspecialchars($_POST['mobile'], ENT_QUOTES, 'UTF-8');