PT-2024-31870 · Unknown · Blood Bank/Donation Management System

Sourajeet Majumder

·

Published

2024-09-26

·

Updated

2025-05-14

·

CVE-2024-45984

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Blood Bank And Donation Management System version 1.0
Description A Cross Site Scripting (XSS) issue in the add donor.php file allows an attacker to inject malicious scripts that will be executed when the Donor List is viewed. This enables the attacker to potentially steal user data or take control of user sessions.
Recommendations For Blood Bank And Donation Management System version 1.0, consider disabling the add donor.php file or restricting access to it until a patch is available to prevent exploitation of the XSS vulnerability. Additionally, avoid using the Donor List feature in the affected version to minimize the risk of malicious script injection. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-45984

Affected Products

Blood Bank/Donation Management System