CVE-2025-63534

HIGH

Blood Bank Management System 1.0 - XSS

Title source: llm
STIX 2.1

Description

A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the login.php component. The application fails to properly sanitize or encode user-supplied input before rendering it in response. An attacker can inject malicious JavaScript payloads into the msg and error parameters, which are then executed in the victim's browser when the page is viewed.

Scores

CVSS v3 8.5
EPSS 0.0002
EPSS Percentile 6.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
shridharshukl/blood_bank_management_system 1.0
Published Dec 01, 2025
Tracked Since Feb 18, 2026