{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/online-birth-certificate-system-1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:phpgurukul:online_birth_certificate_system:1.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.4,"id":"CVE-2024-57175"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Online Birth Certificate System (1.0)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Phpgurukul"],"content_html":"\u003cp\u003eA stored cross-site scripting (XSS) vulnerability exists in the Phpgurukul Online Birth Certificate System version 1.0. The vulnerability resides within the 'profile_name' parameter of the '/user/certificate-form.php' script. An attacker with authenticated access can inject malicious JavaScript payloads into the profile name field. When this data is rendered by the application, the payload executes within the victim's browser session. This vulnerability poses a risk to data integrity and session security, as an attacker could potentially steal session tokens or manipulate the victim's view of the application. The vulnerability is identified as CVE-2024-57175 and carries a CVSS score of 5.4. Public proof-of-concept code is available, increasing the likelihood of exploitation by malicious actors targeting this specific application.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains valid credentials for a standard user account in the Phpgurukul Online Birth Certificate System.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates to the application using these credentials.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the 'certificate-form.php' endpoint within the user portal.\u003c/li\u003e\n\u003cli\u003eAttacker intercepts or crafts a POST request to update the profile information.\u003c/li\u003e\n\u003cli\u003eAttacker injects a malicious JavaScript payload (e.g., \u0026lt;script\u0026gt;alert(1)\u0026lt;/script\u0026gt;) into the 'profile_name' parameter.\u003c/li\u003e\n\u003cli\u003eThe application stores the malicious payload in the underlying database without proper sanitization.\u003c/li\u003e\n\u003cli\u003eA victim user (or the attacker) accesses the page where the profile name is rendered.\u003c/li\u003e\n\u003cli\u003eThe victim's browser renders the stored payload, executing the JavaScript in the user's session context.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary client-side code execution in the context of the user's browser. This can lead to unauthorized actions performed on behalf of the user, theft of session cookies, or the exfiltration of sensitive information displayed on the page.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImplement strict input validation and sanitization for all user-supplied data, specifically for the 'profile_name' field in the 'certificate-form.php' script.\u003c/li\u003e\n\u003cli\u003eEmploy context-aware output encoding when rendering user-generated content in the browser to neutralize potential XSS payloads.\u003c/li\u003e\n\u003cli\u003eEnforce the use of a Content Security Policy (CSP) to restrict the sources from which scripts can be executed.\u003c/li\u003e\n\u003cli\u003eEnsure all authenticated sessions are protected by modern browser security headers to mitigate session hijacking risks.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-29T20:48:38Z","date_published":"2026-08-29T20:48:38Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2024-57175/","summary":"Phpgurukul Online Birth Certificate System version 1.0 is vulnerable to Stored Cross-Site Scripting (XSS) via the profile name field, allowing authenticated attackers to execute arbitrary JavaScript in the context of other users.","title":"Stored XSS Vulnerability in Phpgurukul Online Birth Certificate System","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2024-57175/"}],"language":"en","title":"CraftedSignal Threat Feed - Online Birth Certificate System (1.0)","version":"https://jsonfeed.org/version/1.1"}