Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

A vulnerability was found in code-projects Blood Bank System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/campsdetails.php. The manipulation of the argument hospital/address/city/contact leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "hospital".

CVSS 4 Total

ScoreSeverityVersionVector String
5.3MEDIUM4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
3.5LOW3.1CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
3.5LOW3.0CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
4.02.0AV:N/AC:L/Au:S/C:N/I:P/A:N

Product Status

Learn more

Versions 1 Total

Default Status: unknown

affected

Credits

  • sqliii (VulDB User) reporter
  • sqliii (VulDB User) analyst

Authorized Data Publishers