Required CVE Record Information
Description
A vulnerability was found in code-projects Blood Bank System 1.0. It has been classified as critical. This affects an unknown part of the file /update.php. The manipulation of the argument name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS 4 Total
Score | Severity | Version | Vector String |
---|---|---|---|
5.3 | MEDIUM | 4.0 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
6.3 | MEDIUM | 3.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
6.3 | MEDIUM | 3.0 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
6.5 | — | 2.0 | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Credits
- RonenWen (VulDB User) reporter
- RonenWen (VulDB User) analyst
References 5 Total
- vuldb.com: VDB-279969 | code-projects Blood Bank System update.php sql injection vdb-entrytechnical-description
- vuldb.com: VDB-279969 | CTI Indicators (IOB, IOC, TTP, IOA) signaturepermissions-required
- vuldb.com: Submit #421134 | code-projects blood-bank-system-in-php v1.0 SQL Injection third-party-advisory
- https://github.com/RonenWen/cve/blob/main/sql6-update-name.md exploitpatch
- https://code-projects.org/ product