CVE-2025-0844 | Library-Card-System | Stored Cross Site Scripting In signup.php |
Hi All, I am Maloy Roy Orko . CVE Number: CVE-2025-0844 Recently in one of my pentest research, I found a Library-Card-System application By Needyamin which is an open source Library-Card-System to print a library card with student information using PHP, MYSQL, JAVASCRIPT. It is based on the scripting languages of PHP. Library-Card-System is a Library-Card-S ystem using PHP, MYSQL, JAVASCRIPT Curious to explore its functionalities, I downloaded and set it up in my local system. After fiddling with the source code, I found that it did not have any kind of XSS Protection in signup. php file. It can lead into : Malware Distribution Admin & User Account Takeover Data Breach Users Into Risk Reputation Damage The Main Thing Is, If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too.Thats why I am trying to inform everyone about this . Title of the ...