CVE-2022-40470

MEDIUM

Phpgurukul Blood Donor Management System 1.0 - Cross-Site Scripting via Add Blood Group Name Feature

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-40470. PoCs published by RashidKhanPathan.

AI-analyzed exploit summary This repository contains a writeup for CVE-2022-40470, detailing a Cross-Site Scripting (XSS) vulnerability in Phpgurukul Blood Donor Management System 1.0. The vulnerability allows an attacker to inject arbitrary code via the 'Add Blood Group Name' feature, which executes when navigating to the 'Manage Blood Group' section.

Description

Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature.

Exploits (1)

nomisec WRITEUP 2 stars
by RashidKhanPathan · poc
https://github.com/RashidKhanPathan/CVE-2022-40470

This repository contains a writeup for CVE-2022-40470, detailing a Cross-Site Scripting (XSS) vulnerability in Phpgurukul Blood Donor Management System 1.0. The vulnerability allows an attacker to inject arbitrary code via the 'Add Blood Group Name' feature, which executes when navigating to the 'Manage Blood Group' section.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Phpgurukul Blood Donor Management System Using CodeIgniter - 1.0
Auth required
Prerequisites: Admin credentials · Access to the 'Add Blood Group Name' feature
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 4.8
EPSS 0.0063
EPSS Percentile 45.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
phpgurukul/blood_donor_management_system 1.0
Published Nov 21, 2022
Tracked Since Feb 18, 2026