PHPGURUKUL Online Birth Certificate System Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in PHPGURUKUL Online Birth Certificate System version 1.0. The issue arises in the '/user/certificate-form.php' page, where authenticated users can inject malicious scripts into the profile name field. This injection can lead to the execution of arbitrary JavaScript on the client side, with potential consequences such as data theft or session hijacking.

Impact

Exploitation of this vulnerability allows for the execution of injected scripts in the context of the user's browser, which could be used to steal data, hijack user sessions, or perform other malicious actions.

Reproduction

To reproduce this vulnerability, log in as an authenticated user and navigate to '/user/certificate-form.php'. Once there, enter a profile name that includes an XSS payload, such as a script tag referencing an external script.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
1.7
exploitability
6.5
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.