Cross-Site Request Forgery Vulnerability in PHPGurukul Blood Bank & Donor Management System
CVE-2024-12955
Key Information:
- Vendor
PHPgurukul
- Vendor
- CVE Published:
- 26 December 2024
What is CVE-2024-12955?
A vulnerability has been identified in the PHPGurukul Blood Bank & Donor Management System version 2.4, specifically affecting the /logout.php file. This flaw allows for an attacker to exploit the application through cross-site request forgery (CSRF). As a result of this vulnerability, unauthorized users can potentially manipulate user sessions or perform actions on behalf of authenticated users without their consent. Given that the exploit can be initiated remotely, it is crucial for users of this system to assess their security measures and apply necessary patches or modifications to safeguard against potential attacks. For further details, users are advised to consult official advisories and consider implementing strict CSRF protections.
Affected Version(s)
Blood Bank & Donor Management System 2.4
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
