← Back to browse · API

CVE-2025-63531

Severity
CRITICAL
CVSS
10.0
EPSS
0.00656
Risk score
40.23
CISA KEV
No
PoC
No
Published
2025-12-01
Modified
2025-12-01
First seen
2026-08-07
Aliases
EUVD-2025-199995, GHSA-Q2HP-7CFJ-73M5
Products
n/a:n/a n/a
Sources
euvd EUVD-2025-199995

Description

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properly sanitize user-supplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the remail and rpassword fields, an attacker can bypass authentication and gain unauthorized access to the system.

References