PT-2025-48455 · Unknown · Blood Bank Management System

Published

2025-12-01

·

Updated

2026-01-06

·

CVE-2025-63525

CVSS v3.1

9.6

Critical

VectorAC:L/AV:N/A:N/C:H/I:H/PR:L/S:C/UI:N
Name of the Vulnerable Software and Affected Versions Blood Bank Management System version 1.0
Description An issue exists in Blood Bank Management System version 1.0 that allows authenticated attackers to perform actions with escalated privileges. This is achieved by sending a crafted request to the ''delete.php'' endpoint. The issue allows authenticated users to execute administrative functions.
Recommendations Blood Bank Management System version 1.0: Address the crafted request handling in the ''delete.php'' endpoint to prevent privilege escalation.

Exploit

Fix

LPE

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-63525

Affected Products

Blood Bank Management System