PT-2025-22664 · Unknown · Phpgurukul Medical Card Generation System

Published

2025-05-23

·

Updated

2025-05-24

·

CVE-2024-51107

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHPGURUKUL Medical Card Generation System version 1.0
Description The issue concerns stored cross-site scripting (XSS) vulnerabilities in the /mcgs/admin/contactus.php component. Attackers can execute arbitrary web scripts or HTML by injecting a crafted payload into the pagetitle, pagedes, and email parameters.
Recommendations For PHPGURUKUL Medical Card Generation System version 1.0, consider disabling the /mcgs/admin/contactus.php component until a patch is available to prevent exploitation of the stored XSS vulnerabilities. Restrict access to the pagetitle, pagedes, and email parameters in the affected component to minimize the risk of arbitrary script execution.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-51107

Affected Products

Phpgurukul Medical Card Generation System