CVE-2025-63535

CRITICAL

Blood Bank Management System 1.0 - SQL Injection

Title source: llm
STIX 2.1

Description

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The application fails to properly sanitize usersupplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the search field, an attacker can bypass authentication and gain unauthorized access to the system.

Scores

CVSS v3 9.6
EPSS 0.0008
EPSS Percentile 23.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
shridharshukl/blood_bank_management_system 1.0
Published Dec 01, 2025
Tracked Since Feb 18, 2026