PT-2025-48460 · Unknown · Blood Bank Management System

Published

2025-12-01

·

Updated

2025-12-26

·

CVE-2025-63531

CVSS v3.1
10
VectorAC:L/AV:N/A:N/C:H/I:H/PR:N/S:C/UI:N
Name of the Vulnerable Software and Affected Versions Blood Bank Management System version 1.0
Description A SQL injection issue exists in the Blood Bank Management System 1.0 within the
receiverLogin.php
component. The application does not properly sanitize user-supplied input used in SQL queries. An attacker can inject arbitrary SQL code by manipulating the
remail
and
rpassword
fields. This allows bypassing authentication and gaining unauthorized access to the system.
Recommendations Apply proper input sanitization to all user-supplied data used in SQL queries within the
receiverLogin.php
component.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-63531

Affected Products

Blood Bank Management System