CVE-2025-50367: XSS
Published Jun 27, 2025
·Updated
A stored blind XSS vulnerability exists in the Contact Page of the Phpgurukul Medical Card Generation System 1.0 mcgs/contact.php. The name field fails to properly sanitize user input, allowing an attacker to inject malicious JavaScript.
Affected Software
2 affected components
Phpgurukul Medical Card Generation System
Anujk305 Medical Card Generation System=1.0
Event History
Jun 27, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-50367?
CVE-2025-50367 is considered a high severity vulnerability due to the potential for stored cross-site scripting attacks.
2
How do I fix CVE-2025-50367?
To fix CVE-2025-50367, ensure that user inputs in the name field are properly sanitized to prevent malicious script injections.
3
What systems are affected by CVE-2025-50367?
CVE-2025-50367 affects the Phpgurukul Medical Card Generation System version 1.0.
4
What type of attack does CVE-2025-50367 enable?
CVE-2025-50367 enables stored blind cross-site scripting attacks.
5
Can CVE-2025-50367 affect users' data?
Yes, CVE-2025-50367 can compromise users' data by executing malicious scripts in their browsers.