PHPGURUKUL Medical Card Generation System Stored Cross-Site Scripting Vulnerability

Vulnerability

Stored cross-site scripting vulnerabilities have been identified in PHPGURUKUL Medical Card Generation System version 1.0. These vulnerabilities allow attackers to execute arbitrary web scripts or HTML by injecting crafted payloads into the pagetitle, pagedes, and email parameters within the /mcgs/admin/contactus.php component.

Impact

Exploitation of these vulnerabilities allows for stored cross-site scripting, where injected scripts are executed in the context of the user.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
1.0
exploitability
7.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.