PT-2024-16085 · Unknown · Code-Projects Blood Bank System

Cdl1

·

Published

2024-10-19

·

Updated

2024-10-21

·

CVE-2024-10171

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions code-projects Blood Bank System version 1.0
Description A critical vulnerability was found in the code-projects Blood Bank System. The issue affects an unknown function of the file /admin/massage.php. The manipulation of the bid argument leads to SQL injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations For code-projects Blood Bank System version 1.0, consider disabling access to the /admin/massage.php file until a patch is available. Restrict the manipulation of the bid argument to minimize the risk of SQL injection exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-10171

Affected Products

Code-Projects Blood Bank System