CVE-2025-44181: XSS
Published May 15, 2025
·Updated
Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/add-brand.php via the brandname parameter.
Affected Software
2 affected components
Phpgurukul Vehicle Record Management System
Anujk305 Vehicle Record Management System=1.0
Event History
May 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-44181?
CVE-2025-44181 is classified as a moderate severity Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-44181?
To fix CVE-2025-44181, sanitize input from the brandname parameter to prevent script injection.
3
What software is affected by CVE-2025-44181?
CVE-2025-44181 affects versions of the Phpgurukul Vehicle Record Management System v1.0.
4
Can CVE-2025-44181 lead to data theft?
Yes, if exploited, CVE-2025-44181 can potentially allow attackers to execute scripts in the context of the user's session, leading to data theft.
5
Is user interaction required for CVE-2025-44181 exploitation?
Yes, exploitation of CVE-2025-44181 typically requires user interaction to click on a malicious link or script.