PT-2025-48457 · Unknown · Blood Bank Management System

Published

2025-12-01

·

Updated

2025-12-01

·

CVE-2025-63527

CVSS v3.1

8.5

High

VectorAC:L/AV:N/A:N/C:H/I:L/PR:L/S:C/UI:N
Name of the Vulnerable Software and Affected Versions Blood Bank Management System version 1.0
Description The application does not properly sanitize or encode user-supplied input before rendering it, leading to a cross-site scripting (XSS) issue. An attacker can inject malicious JavaScript payloads into the hname, hemail, hpassword, and hphone parameters of the updateprofile.php and hprofile.php components. When a victim views the page, the injected script is executed in their browser. The vulnerable parameters are used in the ''updateprofile.php'' and ''hprofile.php'' components.
Recommendations Blood Bank Management System version 1.0: Properly sanitize or encode user-supplied input before rendering it in the response to prevent XSS attacks. Specifically, address the hname, hemail, hpassword, and hphone parameters in the ''updateprofile.php'' and ''hprofile.php'' components.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-63527

Affected Products

Blood Bank Management System