Shridharshukl Blood Bank Management System
cpe:2.3:a:blood_bank_management_system_project:blood_bank_management_system:*:*:*:*:*:*:*
- 1.0
A SQL injection vulnerability has been identified in Blood Bank Management System version 1.0, specifically within the cancel.php component. The vulnerability arises because the application does not adequately sanitize user input in SQL queries. This flaw allows attackers to inject arbitrary SQL code, potentially bypassing authentication and gaining unauthorized access to the system.
Exploitation of this vulnerability allows attackers to perform SQL injection, with the potential to manipulate database queries, access or modify database information, and bypass authentication.
To reproduce this vulnerability, log into the application and navigate to the sentrequest.php page. Inject SQL code into the request ID parameter of the cancel.php component to exploit the SQL injection vulnerability. This can be done by manipulating the search field to include malicious SQL code, which can then be executed by the database.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.