Description
Bank Locker Management System by PHPGurukul is affected by a Cross-Site Scripting (XSS) vulnerability via the /search parameter, where unsanitized input allows arbitrary HTML and JavaScript injection, potentially resulting in information disclosure and user redirection.
References
phpgurukul.com/...ker-management-system-using-php-and-mysql/
github.com/...Reports/blob/Master/CVE-2025-61255/advisory.md