CVE-2025-57145

A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The application fails to properly sanitize user input submitted through a form field, allowing an attacker to inject arbitrary JavaScript code. The malicious payload is stored in the backend and executed when a user or administrator accesses the affected report page. This allows attackers to exfiltrate session cookies, hijack user sessions, and perform unauthorized actions in the context of the victims browser.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpgurukul:auto_taxi_stand_management_system:1.0:*:*:*:*:*:*:*

History

08 Oct 2025, 19:25

Type Values Removed Values Added
First Time Phpgurukul auto Taxi Stand Management System
Phpgurukul
CPE cpe:2.3:a:phpgurukul:auto_taxi_stand_management_system:1.0:*:*:*:*:*:*:*
References () http://auto.com - () http://auto.com - Not Applicable
References () http://phpgurukul.com - () http://phpgurukul.com - Product
References () https://github.com/nandanacp/CVE-Collection/blob/main/CVE-2025-57145/README.md - () https://github.com/nandanacp/CVE-Collection/blob/main/CVE-2025-57145/README.md - Third Party Advisory

16 Sep 2025, 19:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
References () https://github.com/nandanacp/CVE-Collection/blob/main/CVE-2025-57145/README.md - () https://github.com/nandanacp/CVE-Collection/blob/main/CVE-2025-57145/README.md -

16 Sep 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-16 15:15

Updated : 2025-10-08 19:25


NVD link : CVE-2025-57145

Mitre link : CVE-2025-57145

CVE.ORG link : CVE-2025-57145


JSON object : View

Products Affected

phpgurukul

  • auto_taxi_stand_management_system
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')