CVE-2024-10448

MEDIUM

Blood Bank Management System 1.0 - Cross-Site Request Forgery via /file/delete.php bid Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-10448. PoCs published by bevennyamande.

AI-analyzed exploit summary The repository contains a functional CSRF PoC for CVE-2024-10448, targeting the BloodBank Management System 1.0. The exploit uses a JavaScript loop to send GET requests to delete blood records via the vulnerable endpoint `/file/delete.php?bid=`.

Description

A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0. Affected by this issue is some unknown functionality of the file /file/delete.php. The manipulation of the argument bid leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other endpoints might be affected as well.

Exploits (1)

nomisec WORKING POC
by bevennyamande · poc
https://github.com/bevennyamande/CVE-2024-10448

The repository contains a functional CSRF PoC for CVE-2024-10448, targeting the BloodBank Management System 1.0. The exploit uses a JavaScript loop to send GET requests to delete blood records via the vulnerable endpoint `/file/delete.php?bid=`.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: BloodBank Management System 1.0
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the PoC
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.282008
Permissions Required, Third Party Advisory, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.282008
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.432501
Product product
https://code-projects.org/

Scores

CVSS v3 4.3
EPSS 0.0039
EPSS Percentile 31.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (1)
fabian/blood_bank_management_system 1.0
Published Oct 28, 2024
Tracked Since Feb 18, 2026