Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-56605 PoC — PuneethReddyHC Event Management 安全漏洞

Source
Associated Vulnerability
Title:PuneethReddyHC Event Management 安全漏洞 (CVE-2025-56605)
Description:PuneethReddyHC Event Management是Puneeth Reddy H C个人开发者的一个应用程序。用简单的逻辑和安全的方式帮助用户注册大学节日中举办的活动。 PuneethReddyHC Event Management 1.0版本存在安全漏洞,该漏洞源于register.php后端脚本对mobile POST参数验证不当,可能导致反射型跨站脚本攻击。
Description
XSS (Cross-Site Scripting Vulnerability)
Readme
# CVE-2025-56605
XSS (Cross-Site Scripting Vulnerability)

# CVE-2025-56605 — Reflected XSS in Event Management System 1.0

**Description:**  
A reflected Cross-Site Scripting (XSS) vulnerability exists in `register.php` of [PuneethReddyHC/event-management](https://github.com/PuneethReddyHC/event-management) 1.0.  
The `mobile` POST parameter is improperly validated and reflected back in the response, allowing injection of arbitrary JavaScript code.

**CVE ID:** CVE-2025-56605  
**Discovered by:** Isroil Mustafoqulov  
**Vulnerability type:** Reflected XSS  
**Attack vector:** Remote  

**Steps to reproduce (local only):**
1. Clone the project and run it locally.  
2. Send a crafted POST request to `backend/register.php` with a malicious payload in the `mobile` parameter.  
3. The payload is reflected unsanitized in the response.  

> ⚠️ Payloads are intentionally omitted. Do not attempt exploitation on systems you do not own.  

**Mitigation:**  
Sanitize/encode user input before output. Example in PHP:  
```php
echo htmlspecialchars($_POST['mobile'], ENT_QUOTES, 'UTF-8');
File Snapshot

[4.0K] /data/pocs/2313fd2d0b67996223e04f1fb7a74573356ca055 └── [1.1K] README.md 0 directories, 1 file
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.