Impact
An undisclosed function in the file /admin/campsdetails.php of itsourcecode Online Blood Bank Management System 1.0 is vulnerable to SQL injection when the hospital parameter is manipulated. Exploitation allows an attacker to inject arbitrary SQL statements, which can lead to data compromise, unauthorized viewing of sensitive information, and modification of database records. The flaw is a classic SQL injection (CWE-74) and is reported to be exploitable remotely.
Affected Systems
Vendors: itsourcecode. Product: Online Blood Bank Management System version 1.0. The affected component is an unknown function within the campsdetails.php script of the administration interface.
Risk and Exploitability
The flaw carries a CVSS score of 6.9, indicating moderate to high severity. The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, but a publicly released exploit is available. The attack vector is remote, meaning an adversary can trigger the injection over the network. Although no specific prerequisites are described, the ability to send manipulated requests suffices to exploit the flaw.
OpenCVE Enrichment