CVE-2024-10448
MEDIUMBlood Bank Management System 1.0 - Cross-Site Request Forgery via /file/delete.php bid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-10448. PoCs published by bevennyamande.
AI-analyzed exploit summary The repository contains a functional CSRF PoC for CVE-2024-10448, targeting the BloodBank Management System 1.0. The exploit uses a JavaScript loop to send GET requests to delete blood records via the vulnerable endpoint `/file/delete.php?bid=`.
Description
A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0. Affected by this issue is some unknown functionality of the file /file/delete.php. The manipulation of the argument bid leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other endpoints might be affected as well.
Exploits (1)
The repository contains a functional CSRF PoC for CVE-2024-10448, targeting the BloodBank Management System 1.0. The exploit uses a JavaScript loop to send GET requests to delete blood records via the vulnerable endpoint `/file/delete.php?bid=`.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N