CVE-2025-63532
01.12.2025, 16:15
A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The application fails to properly sanitize user-supplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the search field, an attacker can bypass authentication and gain unauthorized access to the system.
| Vendor | Product | Version |
|---|---|---|
| shridharshukl | blood_bank_management_system | 1.0 |
𝑥
= Vulnerable software versions