First published: Fri Sep 08 2023(Updated: )
Multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name, Message, or Address parameters.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Blood Bank \& Donor Management System Project Blood Bank \& Donor Management System | =2.2 | |
Phpgurukul Blood Bank \& Donor Management System | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41575 is a vulnerability that allows attackers to execute arbitrary web scripts or HTML through multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2.
CVE-2023-41575 has a severity rating of medium, with a CVSS score of 5.4.
Attackers can exploit CVE-2023-41575 by injecting a crafted payload into the Full Name, Message, or Address parameters in /bbdms/sign-up.php.
Blood Bank & Donor Management v2.2 is affected by CVE-2023-41575.
At the moment, there is no known fix for CVE-2023-41575. It is recommended to apply any patches or updates provided by the software vendor.