VendorsAnujk305medical_card_generation_system1.0
Vulnerabilities

Anujk305 Anuj Kumar Medical Card Generation System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2024-10297
PHPGurukul Medical Card Generation System Managecard Edit Image Page changeimage.php sql injection
Published 2024-10-23 · Analyzed
7.2EPSS 0.005
CVE-2025-50369
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Manage Card functionality (/mcgs/admin/manage-card.php) of PHPGurukul Medical Card Generation System 1.0. The vulnerable endpoint allows an authorized admin to delete medical card records by sending a simple GET request without verifying the origin of the request.
Published 2025-06-27 · Analyzed
6.5EPSS 0.002
CVE-2025-50370
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Inquiry Management functionality /mcgs/admin/readenq.php of the Phpgurukul Medical Card Generation System 1.0. The vulnerable endpoint allows an authenticated admin to delete inquiry records via a simple GET request, without requiring a CSRF token or validating the origin of the request.
Published 2025-06-27 · Analyzed
6.5EPSS 0.002
CVE-2025-50367
A stored blind XSS vulnerability exists in the Contact Page of the Phpgurukul Medical Card Generation System 1.0 mcgs/contact.php. The name field fails to properly sanitize user input, allowing an attacker to inject malicious JavaScript.
Published 2025-06-27 · Analyzed
6.1EPSS 0.002
CVE-2024-51108
Multiple stored cross-site scripting (XSS) vulnerabilities in the component /admin/card-bwdates-report.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the fromdate and todate parameters.
Published 2025-05-23 · Modified
5.4EPSS 0.002
CVE-2024-48703
PhpGurukul Medical Card Generation System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/search-medicalcard.php via the searchdata parameter.
Published 2024-12-06 · Modified
4.8EPSS 0.003
CVE-2024-51107
Multiple stored cross-site scripting (XSS) vulnerabilities in the component /mcgs/admin/contactus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle, pagedes, and email parameters.
Published 2025-05-23 · Modified
4.8EPSS 0.003
CVE-2024-51106
A cross-site scripting (XSS) vulnerability in the component mcgs/admin/aboutus.php of PHPGURUKUL Medical Card Generation System using PHP and MySQL v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the pagetitle parameter.
Published 2025-05-19 · Analyzed
4.6EPSS 0.002