CVE-2025-2037: code-projects Blood Bank Management System delete_requester.php sql injection
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /userdashboard/deleterequester.php. The manipulation of the argument requesterid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2037?
CVE-2025-2037 has been declared as critical due to its potential for SQL injection vulnerabilities.
How do I fix CVE-2025-2037?
To fix CVE-2025-2037, ensure proper input validation and parameterized queries in the /user_dashboard/delete_requester.php file.
What type of vulnerability is CVE-2025-2037?
CVE-2025-2037 is identified as an SQL injection vulnerability affecting certain code in the Blood Bank Management System.
Which software is affected by CVE-2025-2037?
CVE-2025-2037 affects the Blood Bank Management System version 1.0 developed by code-projects.
What is the attack vector of CVE-2025-2037?
The attack vector for CVE-2025-2037 involves manipulating the requester_id parameter in the delete_requester.php file.