Description

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Inquiry Management functionality /mcgs/admin/readenq.php of the Phpgurukul Medical Card Generation System 1.0. The vulnerable endpoint allows an authenticated admin to delete inquiry records via a simple GET request, without requiring a CSRF token or validating the origin of the request.

INFO

Published Date :

2025-06-27T00:00:00.000Z

Last Modified :

2025-06-27T20:05:20.588Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-50370 vulnerability.

Vendors Products
Anujk305
  • Medical Card Generation System
Phpgurukul
  • Medical Card Generation System
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-50370.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact