CRITICAL🇵🇱 Wersja polska

CVE-2025-63535

CVSS 9.6v3.1pub. 2025-12-01upd. 2025-12-03

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The application fails to properly sanitize usersupplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the search field, an attacker can bypass authentication and gain unauthorized access to the system.

🤖 AI Analysis
How it works

The application does not properly sanitize user-supplied data before placing it in SQL queries. An attacker can manipulate the search field by injecting arbitrary SQL code. As a result, it is possible to bypass the authentication mechanism and gain unauthorized access to the system without knowing the correct credentials.

Impact

An attacker can bypass authentication and gain unauthorized access to the system, as well as read or modify data stored in the database (high risk to data confidentiality and integrity).

Mitigation & patch

Patches available from the vendor should be applied according to the references. As an interim security measure, it is recommended to implement parameterized SQL queries (prepared statements) and validation and sanitization of input data on the server side. Until a patch is released, consider restricting access to the application only to trusted networks.

Who is affected

Blood Bank Management System version 1.0 (abs.php component), authored by Shridharshukl

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  • Shridharshukl Blood Bank Management System

    APP
    Shridharshukl
    1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLiAuth Bypass
CWE
References

Related vulnerabilities

CVE-2025-63531CRITICAL10.0PL ✓same product

SQL Injection z pominięciem uwierzytelnienia w Blood Bank Management System

CVE-2025-63532CRITICAL9.6PL ✓same product

SQL Injection w Blood Bank Management System — obejście uwierzytelnienia

CVE-2025-63525CRITICAL9.6PL ✓same product

Eskalacja uprawnień w Blood Bank Management System 1.0 (delete.php)

CVE-2025-63528HIGH8.5same product

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the blooddinf...

CVE-2025-63533HIGH8.5same product

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updatepro...