Impact
The vulnerability is located in the file editcampaignform.php of Simple Blood Donor Management System 1.0. Manipulating the ID parameter allows an attacker to inject arbitrary SQL commands into the database query, enabling read, modify, or delete operations on donor and campaign data. This weakness corresponds to the classic SQL injection flaw identified as CWE-74 and CWE-89.
Affected Systems
The affected product is the Simple Blood Donor Management System version 1.0 from the vendor code-projects. No other version or vendor information is provided.
Risk and Exploitability
The CVSS score of 6.9 signals a moderate to high severity, while the EPSS score of less than 1% indicates a low but nonzero probability of exploitation. The vulnerability can be triggered remotely via the web interface without requiring elevated privileges, and it is not listed in the CISA KEV catalog. The reported exploit is publicly available and could be used against any exposed instance of the application.
OpenCVE Enrichment