Cross Site Scripting in Phpgurukul Blood Donor Management System
CVE-2022-40470
4.8MEDIUM
Key Information:
- Vendor
PHPgurukul
- Vendor
- CVE Published:
- 21 November 2022
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2022-40470?
The Blood Donor Management System version 1.0 by Phpgurukul is prone to a Cross Site Scripting (XSS) vulnerability, allowing attackers to inject malicious scripts via the Add Blood Group Name feature. This flaw can lead to unauthorized access to sensitive user data and potentially compromise the security of the application.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
