CRITICAL🇵🇱 Wersja polska

CVE-2025-63525

CVSS 9.6v3.1pub. 2025-12-01upd. 2026-01-06

An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted request to delete.php.

🤖 AI Analysis
How it works

An attacker who has an active user session (of any level) can send a crafted HTTP request to the delete.php file. This request bypasses proper privilege verification (CWE-284 — improper access control), allowing execution of operations reserved for higher-privileged accounts. The error results from a lack of proper identity validation and privilege level verification on the server side before executing sensitive actions.

Impact

An authenticated attacker can perform unauthorized data deletion operations and other actions reserved for administrators, which may lead to violations of integrity and confidentiality of data stored in the blood bank management system.

Mitigation & patch

Patches available from the vendor should be applied according to the references. As a temporary measure, it is recommended to restrict application access only to trusted, authorized users and to monitor requests directed to the delete.php file for unauthorized calls.

Who is affected

Blood Bank Management System version 1.0 by Shridharshukl

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  • Shridharshukl Blood Bank Management System

    APP
    Shridharshukl
    1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-63535CRITICAL9.6PL ✓same product

SQL Injection i Auth Bypass w Blood Bank Management System 1.0

CVE-2025-63531CRITICAL10.0PL ✓same product

SQL Injection z pominięciem uwierzytelnienia w Blood Bank Management System

CVE-2025-63532CRITICAL9.6PL ✓same product

SQL Injection w Blood Bank Management System — obejście uwierzytelnienia

CVE-2025-63534HIGH8.5same product

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the login.php...

CVE-2025-63526HIGH8.5same product

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System within the abs.php compo...