CVE-2024-7321

MEDIUM

Online Blood Bank Management System 1.0 - Cross-Site Scripting via User Registration Handler

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-7321. PoCs published by cl4irv0yance.

AI-analyzed exploit summary The repository contains detailed technical writeups for multiple CVEs (CVE-2024-7303, CVE-2024-7320, CVE-2024-7321) affecting the Online Blood Bank Management System v1.0. Each writeup includes root cause analysis, proof-of-concept requests, and remediation guidance, demonstrating a deep understanding of the vulnerabilities (XSS and SQL injection).

Description

A vulnerability classified as problematic was found in itsourcecode Online Blood Bank Management System 1.0. This vulnerability affects unknown code of the file signup.php of the component User Registration Handler. The manipulation of the argument user leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273232.

Exploits (1)

github WRITEUP
by cl4irv0yance · poc
https://github.com/cl4irv0yance/CVEs/tree/main/CVE-2024-7321

The repository contains detailed technical writeups for multiple CVEs (CVE-2024-7303, CVE-2024-7320, CVE-2024-7321) affecting the Online Blood Bank Management System v1.0. Each writeup includes root cause analysis, proof-of-concept requests, and remediation guidance, demonstrating a deep understanding of the vulnerabilities (XSS and SQL injection).

Classification
Writeup 100%
Attack Type
Xss | Sqli | Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Online Blood Bank Management System v1.0
No auth needed
Prerequisites: Access to the vulnerable application
devstral-2 · analyzed Feb 27, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit issue-tracking
https://github.com/cl4irv0yance/CVEs/issues/4
VDB Entry third-party-advisory
https://vuldb.com/?submit.383437
Permissions Required vdb-entry technical-description
https://vuldb.com/?id.273232
Permissions Required signature permissions-required
https://vuldb.com/?ctiid.273232

Scores

CVSS v3 4.3
EPSS 0.0052
EPSS Percentile 40.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
adonesevangelista/online_blood_bank_management_system 1.0
Published Jul 31, 2024
Tracked Since Feb 18, 2026