PHPGurukul Medical Card Generation System Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Manage Card functionality of PHPGurukul Medical Card Generation System version 1.0. The issue allows an authorized admin to delete medical card records by sending a simple GET request, without any verification of the request's origin.

Impact

Exploitation of this vulnerability allows for unauthorized deletion of medical card records.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
2.5
exploitability
5.2
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.