CVE-2025-50487: High severity Phpgurukul Blood Bank & Donor Management System vulnerability
Published Jul 28, 2025
·Updated
Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management System v2.4 allows attackers to execute a session hijacking attack.
Affected Software
2 affected components
Phpgurukul Blood Bank & Donor Management System
Phpgurukul Blood Bank \& Donor Management System=2.4
Event History
Jul 28, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-50487?
CVE-2025-50487 has a high severity level due to its potential for session hijacking attacks.
2
How do I fix CVE-2025-50487?
To fix CVE-2025-50487, ensure proper session invalidation after password changes in the affected component.
3
Who is affected by CVE-2025-50487?
CVE-2025-50487 affects users of PHPGurukul Blood Bank & Donor Management System version 2.4.
4
What type of vulnerability is CVE-2025-50487?
CVE-2025-50487 is an improper session invalidation vulnerability.
5
What can attackers do with CVE-2025-50487?
Attackers can exploit CVE-2025-50487 to hijack user sessions and potentially access sensitive information.