PHPGURUKUL Online Birth Certificate System
cpe:2.3:a:phpgurukul:online_birth_certificate_system:*:*:*:*:*:*:*
- 1.0
A stored cross-site scripting vulnerability has been identified in PHPGURUKUL Online Birth Certificate System version 1.0. The issue arises in the '/user/certificate-form.php' page, where authenticated users can inject malicious scripts into the profile name field. This injection can lead to the execution of arbitrary JavaScript on the client side, with potential consequences such as data theft or session hijacking.
Exploitation of this vulnerability allows for the execution of injected scripts in the context of the user's browser, which could be used to steal data, hijack user sessions, or perform other malicious actions.
To reproduce this vulnerability, log in as an authenticated user and navigate to '/user/certificate-form.php'. Once there, enter a profile name that includes an XSS payload, such as a script tag referencing an external script.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.