CVE-2025-57145

MEDIUM

phpgurukul auto_taxi_stand_management_system - Stored Cross-Site Scripting via search-autootaxi.php Form Field

Title source: llm
STIX 2.1

Description

A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The application fails to properly sanitize user input submitted through a form field, allowing an attacker to inject arbitrary JavaScript code. The malicious payload is stored in the backend and executed when a user or administrator accesses the affected report page. This allows attackers to exfiltrate session cookies, hijack user sessions, and perform unauthorized actions in the context of the victims browser.

Scores

CVSS v3 5.4
EPSS 0.0003
EPSS Percentile 7.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
phpgurukul/auto_taxi_stand_management_system 1.0
Published Sep 16, 2025
Tracked Since Feb 18, 2026