Description
A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an unknown function of the file /admin/campsdetails.php. Performing a manipulation of the argument hospital results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-06-01
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An undisclosed function in the file /admin/campsdetails.php of itsourcecode Online Blood Bank Management System 1.0 is vulnerable to SQL injection when the hospital parameter is manipulated. Exploitation allows an attacker to inject arbitrary SQL statements, which can lead to data compromise, unauthorized viewing of sensitive information, and modification of database records. The flaw is a classic SQL injection (CWE-74) and is reported to be exploitable remotely.

Affected Systems

Vendors: itsourcecode. Product: Online Blood Bank Management System version 1.0. The affected component is an unknown function within the campsdetails.php script of the administration interface.

Risk and Exploitability

The flaw carries a CVSS score of 6.9, indicating moderate to high severity. The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, but a publicly released exploit is available. The attack vector is remote, meaning an adversary can trigger the injection over the network. Although no specific prerequisites are described, the ability to send manipulated requests suffices to exploit the flaw.

Generated by OpenCVE AI on June 1, 2026 at 12:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s official patch or upgrade to a fixed version of Online Blood Bank Management System.
  • Implement proper input validation and use parameterized queries for the hospital parameter in campsdetails.php if patch is unavailable.
  • Deploy a web application firewall to block suspicious SQL patterns and monitor administrative access logs for anomalous activity.

Generated by OpenCVE AI on June 1, 2026 at 12:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 01 Jun 2026 11:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an unknown function of the file /admin/campsdetails.php. Performing a manipulation of the argument hospital results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.
Title itsourcecode Online Blood Bank Management System campsdetails.php sql injection
First Time appeared Itsourcecode
Itsourcecode online Blood Bank Management System
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:itsourcecode:online_blood_bank_management_system:*:*:*:*:*:*:*:*
Vendors & Products Itsourcecode
Itsourcecode online Blood Bank Management System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Itsourcecode Online Blood Bank Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-01T10:45:07.426Z

Reserved: 2026-05-31T10:17:05.968Z

Link: CVE-2026-10250

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-06-01T11:16:24.420

Modified: 2026-06-01T13:14:43.470

Link: CVE-2026-10250

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-01T12:30:28Z

Weaknesses