PT-2025-48460 · Unknown · Blood Bank Management System

Published

2025-12-01

·

Updated

2025-12-26

·

CVE-2025-63531

CVSS v3.1

10

Critical

AC:L/AV:N/A:N/C:H/I:H/PR:N/S:C/UI:N
Name of the Vulnerable Software and Affected Versions Blood Bank Management System version 1.0
Description A SQL injection issue exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application does not properly sanitize user-supplied input used in SQL queries. An attacker can inject arbitrary SQL code by manipulating the remail and rpassword fields. This allows bypassing authentication and gaining unauthorized access to the system.
Recommendations Apply proper input sanitization to all user-supplied data used in SQL queries within the receiverLogin.php component.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-63531

Affected Products

Blood Bank Management System