Impact
The vulnerability resides in the constructor of the Admin Dashboard controller, allowing an attacker to bypass the authentication check. By manipulating the request, unauthenticated users can instantiate the controller and gain access to administrative functions. This flaw can lead to unauthorized modification of donor records, administrator settings, and potentially exfiltration of sensitive personal data.
Affected Systems
PHPGurukul’s Blood Donor Management System, version 1.0. No other versions were identified in the CNA data.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate impact, and the absence of an EPSS score and KEV listing suggests that the vulnerability has not yet been widely observed in the wild. Nevertheless, the description notes that the exploit is publicly available and can be triggered remotely, meaning that anyone with internet access can attempt the attack. Given the authentication bypass and remote attack vector, the risk to affected deployments is significant, warranting prompt remediation.
OpenCVE Enrichment