CRITICAL🇵🇱 Wersja polska

CVE-2025-63532

CVSS 9.6v3.1pub. 2025-12-01upd. 2025-12-04

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The application fails to properly sanitize user-supplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the search field, an attacker can bypass authentication and gain unauthorized access to the system.

🤖 AI Analysis
How it works

The application does not perform proper sanitization of user-supplied input data before including it in SQL queries. An attacker can manipulate the search field in the cancel.php component by injecting arbitrary SQL code. This results in the ability to bypass the authentication mechanism (auth bypass) and gain unauthorized access to the system without knowing valid login credentials.

Impact

An attacker with network access to the application can bypass authentication and gain unauthorized access to the blood bank management system, as well as read or modify data stored in the database.

Mitigation & patch

Apply patches available from the vendor according to the references. Until the fix is implemented, it is recommended to restrict access to the application only from trusted networks and implement WAF rules blocking characteristic SQL injection sequences in input fields.

Who is affected

Blood Bank Management System version 1.0 (Shridharshukl)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  • Shridharshukl Blood Bank Management System

    APP
    Shridharshukl
    1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLiAuth Bypass
CWE
References

Related vulnerabilities

CVE-2025-63525CRITICAL9.6PL ✓same product

Eskalacja uprawnień w Blood Bank Management System 1.0 (delete.php)

CVE-2025-63531CRITICAL10.0PL ✓same product

SQL Injection z pominięciem uwierzytelnienia w Blood Bank Management System

CVE-2025-63535CRITICAL9.6PL ✓same product

SQL Injection i Auth Bypass w Blood Bank Management System 1.0

CVE-2025-63528HIGH8.5same product

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the blooddinf...

CVE-2025-63534HIGH8.5same product

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the login.php...