First published: Mon Nov 21 2022(Updated: )
Phpgurukul Blood Donor Management System 1.0 allows Cross Site Scripting via Add Blood Group Name Feature.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Blood Donor Management System Project Blood Donor Management System | =1.0 | |
Phpgurukul Blood Donor Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40470 is a vulnerability in the Phpgurukul Blood Donor Management System 1.0 that allows Cross Site Scripting (XSS) via the Add Blood Group Name feature.
An attacker can exploit CVE-2022-40470 by injecting malicious scripts into the Add Blood Group Name field, which will then be executed by the victim's browser when viewing the affected page.
The severity of CVE-2022-40470 is medium, with a severity value of 4.8.
Phpgurukul Blood Donor Management System 1.0 and Blood Donor Management System Project Blood Donor Management System 1.0 are affected by CVE-2022-40470.
Yes, to fix CVE-2022-40470, it is recommended to apply the latest patches or upgrades provided by the vendor to mitigate the Cross Site Scripting vulnerability.