CVE-2024-10557
MEDIUMBlood Bank Management System 1.0 - Cross-Site Request Forgery in Profile Update Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-10557. PoCs published by bevennyamande.
AI-analyzed exploit summary The repository provides functional CSRF exploit code targeting the BloodBank Management System 1.0 via the `/file/updateprofile.php` endpoint. It includes two PoC HTML files demonstrating profile manipulation and account takeover via chained CSRF attacks.
Description
A vulnerability has been found in code-projects Blood Bank Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /file/updateprofile.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Exploits (1)
The repository provides functional CSRF exploit code targeting the BloodBank Management System 1.0 via the `/file/updateprofile.php` endpoint. It includes two PoC HTML files demonstrating profile manipulation and account takeover via chained CSRF attacks.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N