A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properly sanitize user-supplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the remail and rpassword fields, an attacker can bypass authentication and gain unauthorized access to the system.
History

Tue, 02 Dec 2025 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Shridharshukl
Shridharshukl blood Bank Management System
CPEs cpe:2.3:a:shridharshukl:blood_bank_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Shridharshukl
Shridharshukl blood Bank Management System

Mon, 01 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 01 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Description A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properly sanitize user-supplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the remail and rpassword fields, an attacker can bypass authentication and gain unauthorized access to the system.
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AC:L/AV:N/A:N/C:H/I:H/PR:N/S:C/UI:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-12-01T00:00:00.000Z

Updated: 2025-12-01T18:30:42.119Z

Reserved: 2025-10-27T00:00:00.000Z

Link: CVE-2025-63531

cve-icon Vulnrichment

Updated: 2025-12-01T18:30:13.105Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-01T15:15:51.987

Modified: 2025-12-02T03:03:24.593

Link: CVE-2025-63531

cve-icon Redhat

No data.