SQL Injection Vulnerability in Code-Projects BloodBank Managing System
CVE-2026-7731
Key Information:
- Vendor
Code-projects
- Vendor
- CVE Published:
- 4 May 2026
Badges
What is CVE-2026-7731?
A security vulnerability has been identified in the BloodBank Managing System version 1.0, specifically within the 'get_state.php' file. This vulnerability arises from inadequate validation of the G_STATE_ID parameter, allowing for SQL injection attacks. Attackers can exploit this vulnerability remotely, leading to unauthorized database access and potential data breaches. Public disclosure of this exploit has raised concerns over the security of applications utilizing this system.
Affected Version(s)
BloodBank Managing System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
