PT-2025-48455 · Unknown · Blood Bank Management System

CVE-2025-63525

·

Published

2025-12-01

·

Updated

2026-01-06

CVSS v3.1

9.6

Critical

VectorAC:L/AV:N/A:N/C:H/I:H/PR:L/S:C/UI:N
Name of the Vulnerable Software and Affected Versions Blood Bank Management System version 1.0
Description An issue exists in Blood Bank Management System version 1.0 that allows authenticated attackers to perform actions with escalated privileges. This is achieved by sending a crafted request to the ''delete.php'' endpoint. The issue allows authenticated users to execute administrative functions.
Recommendations Blood Bank Management System version 1.0: Address the crafted request handling in the ''delete.php'' endpoint to prevent privilege escalation.

Exploit

Fix

LPE

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-63525

Affected Products

Blood Bank Management System