Impact
A flaw in the login logic of the PHPGurukul Blood Donor Management System writes passwords and related credentials directly to a file on disk in clear text. This allows an attacker who can submit a modified login request to retrieve and later read the exposed credentials, compromising the confidentiality of user accounts. The weakness is a cleartext storage of sensitive information, classified as CWE-312 and CWE-313. An attacker can trigger this remotely, although the exploitation requires advanced privileges to alter login parameters and a high level of technical skill, and publicly available exploit code has been released.
Affected Systems
The affected product is PHPGurukul Blood Donor Management System version 1.0. The vulnerability resides in the file application/models/admin/Login_Model.php and is specific to this vendor’s implementation.
Risk and Exploitability
The CVSS score of 6.3 indicates a medium severity for this flaw. The EPSS score of < 1% suggests that the likelihood of exploitation is low, though the vulnerability remains remotely exploitable. The flaw is not listed in the CISA KEV catalog. Because the vulnerability can be triggered remotely and public exploit code exists, the risk of data leakage remains significant and should be mitigated promptly.
OpenCVE Enrichment