A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The application fails to properly sanitize user input submitted through a form field, allowing an attacker to inject arbitrary JavaScript code. The malicious payload is stored in the backend and executed when a user or administrator accesses the affected report page. This allows attackers to exfiltrate session cookies, hijack user sessions, and perform unauthorized actions in the context of the victims browser.
References
Link | Resource |
---|---|
http://auto.com | Not Applicable |
http://phpgurukul.com | Product |
https://github.com/nandanacp/CVE-Collection/blob/main/CVE-2025-57145/README.md | Third Party Advisory |
https://github.com/nandanacp/CVE-Collection/blob/main/CVE-2025-57145/README.md | Third Party Advisory |
Configurations
History
08 Oct 2025, 19:25
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:phpgurukul:auto_taxi_stand_management_system:1.0:*:*:*:*:*:*:* | |
References | () http://auto.com - Not Applicable | |
References | () http://phpgurukul.com - Product | |
References | () https://github.com/nandanacp/CVE-Collection/blob/main/CVE-2025-57145/README.md - Third Party Advisory | |
First Time |
Phpgurukul
Phpgurukul auto Taxi Stand Management System |
16 Sep 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 | |
References | () https://github.com/nandanacp/CVE-Collection/blob/main/CVE-2025-57145/README.md - | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
16 Sep 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-16 15:15
Updated : 2025-10-08 19:25
NVD link : CVE-2025-57145
Mitre link : CVE-2025-57145
CVE.ORG link : CVE-2025-57145
JSON object : View
Products Affected
phpgurukul
- auto_taxi_stand_management_system
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')