Blood Bank Management System Privilege Escalation Vulnerability

Vulnerability

A vulnerability in Blood Bank Management System version 1.0 allows authenticated attackers to escalate privileges and perform unauthorized actions. This is achieved by sending crafted requests to the 'delete.php' file, exploiting inadequate access controls.

Impact

Exploitation of this vulnerability enables authenticated users to manipulate records and perform actions with elevated privileges, potentially leading to unauthorized data changes and access to sensitive information.

Reproduction

To reproduce this vulnerability, log into the application as a user with lower privileges. Then, access the 'bloodinfo.php' page and copy the link to a record. Switch the session to a user with higher privileges, such as a hospital role, and modify the request to delete the record. The action will be successfully completed, demonstrating the privilege escalation.

Added: Dec 1, 2025, 3:25 PM
Updated: Dec 1, 2025, 3:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
5.0
exploitability
6.2
remediation
0.0
relevance
1.2
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.