Vulnerabilities (CVE)

Filtered by vendor Phpgurukul Subscribe
Filtered by product Online Birth Certificate System
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-57175 1 Phpgurukul 1 Online Birth Certificate System 2025-03-28 N/A 5.4 MEDIUM
A Stored Cross-Site Scripting (XSS) vulnerability was identified in the PHPGURUKUL Online Birth Certificate System v1.0 via the profile name to /user/certificate-form.php.
CVE-2024-55059 1 Phpgurukul 1 Online Birth Certificate System 2025-03-27 N/A 6.1 MEDIUM
A stored HTML Injection vulnerability was identified in PHPGurukul Online Birth Certificate System v1.0 in /user/certificate-form.php.
CVE-2024-55058 1 Phpgurukul 1 Online Birth Certificate System 2025-03-27 N/A 4.3 MEDIUM
An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1.0. This vulnerability resides in the viewid parameter of /user/view-application-detail.php. Authenticated users can exploit this flaw by manipulating the viewid parameter in the URL to access sensitive birth certificate details of other users without proper authorization checks.
CVE-2024-55057 1 Phpgurukul 1 Online Birth Certificate System 2025-03-27 N/A 5.4 MEDIUM
Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unauthorized access to user accounts.
CVE-2024-55056 1 Phpgurukul 1 Online Birth Certificate System 2025-03-27 N/A 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /user/certificate-form.php via the full name field.