Impact
The flaw resides in the Report.php controller of PHPGurukul Blood Donor Management System 1.0. By manipulating the arguments fromdate and todate, a user can inject arbitrary SQL into backend queries. This injection vulnerability, identified as CWE‑74 and CWE‑89, allows a remote attacker to disclose sensitive data, alter records, or potentially drop tables, thereby compromising confidentiality and integrity of the donor database.
Affected Systems
Only the PHPGurukul Blood Donor Management System, version 1.0, is affected. The vulnerability is present in the Report Endpoint component of CVSS score of 6.9 indicates moderate to high severity. The EPSS score is <1%, but public exploit code has been released and is openly documented, which raises the likelihood of real‑world exploitation. The vulnerability can be triggered remotely via crafted web requests, and the system is listed as not in CISA KEV, meaning no mass compromises have been amplified by the lack of a publicly available patch and the availability of exploit code.
Risk and Exploitability
The flaw allows attackers to inject arbitrary SQL into queries executed by the Report Endpoint module, leading to potential data leakage, unauthorized data modification, or even destruction of database objects. The CVSS score of 6.9 indicates moderate to high severity, and the EPSS score of <1% suggests a low yet non‑zero exploitation probability, while public exploit code has been released and the attack can be launched remotely. As the vulnerability is not listed in CISA KEV, no large‑scale compromise has yet been reported, but the presence of public exploit material raises the likelihood of real‑world attacks, especially against unauthenticated or broadly accessible instances of the system.
OpenCVE Enrichment