CVE-2025-50367: ANUJK305 Medical Card Generation System

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A stored blind XSS vulnerability exists in the Contact Page of the Phpgurukul Medical Card Generation System 1.0 mcgs/contact.php. The name field fails to properly sanitize user input, allowing an attacker to inject malicious JavaScript.

Affected products

  • ANUJK305 Medical Card Generation System: version 1.0 only

Published 2025-06-27. Last modified 2026-06-17.