PT-2024-39418 · Unknown · Blood Bank System
Kev1Nk
·
Published
2024-09-22
·
Updated
2025-08-19
·
CVE-2024-9084
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Blood Bank System version 1.0
Description
A problematic issue was found in the Blood Bank System, affecting unknown parts of the bbms.php file. The manipulation of the
fullname, age, bloodgroup, city, phno, and gender arguments as part of a String leads to cross-site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.Recommendations
For version 1.0, consider disabling the vulnerable parts of the bbms.php file until a patch is available. Restrict access to the bbms.php file to minimize the risk of exploitation. Avoid using the
fullname, age, bloodgroup, city, phno, and gender arguments in the affected API endpoints until the issue is resolved.Exploit
Fix
DoS
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blood Bank System