CVE-2025-50367
- EPSS 0.04%
- Published 27.06.2025 00:00:00
- Last modified 01.07.2025 18:14:15
A stored blind XSS vulnerability exists in the Contact Page of the Phpgurukul Medical Card Generation System 1.0 mcgs/contact.php. The name field fails to properly sanitize user input, allowing an attacker to inject malicious JavaScript.
CVE-2025-50369
- EPSS 0.02%
- Published 27.06.2025 00:00:00
- Last modified 01.07.2025 18:13:49
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Manage Card functionality (/mcgs/admin/manage-card.php) of PHPGurukul Medical Card Generation System 1.0. The vulnerable endpoint allows an authorized admin to delete medical card record...
CVE-2025-50370
- EPSS 0.02%
- Published 27.06.2025 00:00:00
- Last modified 01.07.2025 18:13:30
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Inquiry Management functionality /mcgs/admin/readenq.php of the Phpgurukul Medical Card Generation System 1.0. The vulnerable endpoint allows an authenticated admin to delete inquiry rec...
CVE-2024-51107
- EPSS 0.06%
- Published 23.05.2025 00:00:00
- Last modified 29.05.2025 16:15:39
Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a craf...
CVE-2024-51108
- EPSS 0.05%
- Published 23.05.2025 00:00:00
- Last modified 29.05.2025 16:15:39
Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a...
CVE-2024-51106
- EPSS 0.03%
- Published 19.05.2025 00:00:00
- Last modified 28.05.2025 01:00:45
A cross-site scripting (XSS) vulnerability in the component mcgs/admin/aboutus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into th...
CVE-2024-48703
- EPSS 0.1%
- Published 06.12.2024 18:15:25
- Last modified 11.12.2024 17:15:16
PhpGurukul Medical Card Generation System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/search-medicalcard.php via the searchdata parameter.
CVE-2024-10297
- EPSS 0.07%
- Published 23.10.2024 18:15:05
- Last modified 06.05.2025 17:55:52
A vulnerability was found in PHPGurukul Medical Card Generation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/changeimage.php of the component Managecard Edit Image Page. The manipu...