Cross-Site Request Forgery Vulnerability in PHPGurukul Blood Bank & Donor Management System
CVE-2024-12955

6.9MEDIUM

Key Information:

Vendor

PHPgurukul

Vendor
CVE Published:
26 December 2024

What is CVE-2024-12955?

A vulnerability has been identified in the PHPGurukul Blood Bank & Donor Management System version 2.4, specifically affecting the /logout.php file. This flaw allows for an attacker to exploit the application through cross-site request forgery (CSRF). As a result of this vulnerability, unauthorized users can potentially manipulate user sessions or perform actions on behalf of authenticated users without their consent. Given that the exploit can be initiated remotely, it is crucial for users of this system to assess their security measures and apply necessary patches or modifications to safeguard against potential attacks. For further details, users are advised to consult official advisories and consider implementing strict CSRF protections.

Affected Version(s)

Blood Bank & Donor Management System 2.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kwangyun Keum
Lo1x (VulDB User)
Lo1x (VulDB User)
.