CVE-2025-3306
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 6, 2025
Updated: Apr 8, 2025
CWE ID 74
CWE ID 89
Summary
CVE-2025-3306 is a critical vulnerability affecting the Blood Bank Management System 1.0 by code-projects. The issue involves the processing of the file /don.php, where manipulation of the argument "fullname" can lead to SQL injection. This flaw allows remote attacks, and it has been disclosed to the public, potentially increasing the risk for exploitation. Other parameters may also be susceptible to similar manipulation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Code Projects