SQL Injection Vulnerability in Blood Bank Management System by Code-Projects
CVE-2025-2033
Key Information:
- Vendor
- Code-projects
- Vendor
- CVE Published:
- 6 March 2025
Badges
Summary
A significant security vulnerability has been identified in the Blood Bank Management System 1.0, located in the functionality of the /user_dashboard/view_donor.php file. This vulnerability allows for SQL injection via manipulation of the donor_id parameter, which can be exploited remotely. The potential for unauthorized access to sensitive data poses a grave risk, emphasizing the need for immediate attention to secure the application. This exploit has been made public, drawing attention to the necessity for developers and users to implement protective measures against such threats.
Affected Version(s)
Blood Bank Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved