First published: Sun Apr 06 2025(Updated: )
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /reset.php. The manipulation of the argument useremail leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Blood Bank Management System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3307 is classified as a critical vulnerability.
To fix CVE-2025-3307, sanitize and validate all user inputs, especially the useremail parameter in /reset.php.
CVE-2025-3307 allows for SQL injection attacks due to improper handling of user inputs.
Yes, CVE-2025-3307 can be exploited remotely by attackers.
The vulnerability CVE-2025-3307 affects Blood Bank Management System version 1.0 from code-projects.