First published: Wed Oct 30 2024(Updated: )
A vulnerability classified as critical has been found in code-projects Blood Bank System 1.0. This affects an unknown part of the file /admin/blood/update/B-.php. The manipulation of the argument Bloodname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fabianros Blood Bank Management System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10506 is classified as a critical vulnerability.
CVE-2024-10506 allows for SQL injection via the Bloodname parameter in the /admin/blood/update/B-.php file.
Yes, CVE-2024-10506 can be exploited remotely.
To fix CVE-2024-10506, sanitize and validate user input to prevent SQL injection attacks.
CVE-2024-10506 affects Blood Bank System version 1.0.