CVE-2025-44180: XSS
Published May 15, 2025
·Updated
Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit-brand.php?bid={brandId}.
Affected Software
2 affected components
Phpgurukul Vehicle Record Management System
Anujk305 Vehicle Record Management System=1.0
Event History
May 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-44180?
CVE-2025-44180 has a severity rating of medium due to its potential impact on user data through cross-site scripting (XSS).
2
How do I fix CVE-2025-44180?
To fix CVE-2025-44180, sanitize and validate user input on the /edit-brand.php page to prevent XSS attacks.
3
What impact does CVE-2025-44180 have on the Vehicle Record Management System?
CVE-2025-44180 allows attackers to execute arbitrary JavaScript in the context of the victim's browser, leading to data theft or session hijacking.
4
Is CVE-2025-44180 easy to exploit?
Yes, CVE-2025-44180 can be easily exploited by including malicious scripts in the brand ID parameter in the URL.
5
Which version of Vehicle Record Management System is affected by CVE-2025-44180?
CVE-2025-44180 specifically affects Phpgurukul Vehicle Record Management System version 1.0.