CVE-2025-3307: code-projects Blood Bank Management System reset.php sql injection
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /reset.php. The manipulation of the argument useremail leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3307?
CVE-2025-3307 is classified as a critical vulnerability.
How do I fix CVE-2025-3307?
To fix CVE-2025-3307, sanitize and validate all user inputs, especially the useremail parameter in /reset.php.
What type of attack does CVE-2025-3307 allow?
CVE-2025-3307 allows for SQL injection attacks due to improper handling of user inputs.
Can CVE-2025-3307 be exploited remotely?
Yes, CVE-2025-3307 can be exploited remotely by attackers.
Which software is affected by CVE-2025-3307?
The vulnerability CVE-2025-3307 affects Blood Bank Management System version 1.0 from code-projects.