← Vulnerability feed

Vulnerability record · CVE-2025-63525 · published 1 December 2025

CVE-2025-63525: Shridharshukl blood bank management system improper access control vulnerability

SShridharshukl · Blood Bank Management System

An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted request to delete.php.

8.8 CVSS 3.1 High EPSS 0.49% · top 60.0% CWE-284 · Improper access control
8.8CVSS 3.1 base score
0.49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted request to delete.php.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-63525 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-63531Shridharshukl blood bank management system sql injection vulnerabilityA SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properl…EPSS 0.65%8.8CVE-2025-63535Shridharshukl blood bank management system sql injection vulnerabilityA SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The application fails to properly sanitize…EPSS 0.39%8.8CVE-2025-63532Shridharshukl blood bank management system sql injection vulnerabilityA SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The application fails to properly sanit…EPSS 0.39%8.8CVE-2025-63529Shridharshukl blood bank management system vulnerabilityA session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's session i…EPSS 0.37%5.4CVE-2025-63534Shridharshukl blood bank management system cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the login.php component. The application fails to pr…EPSS 0.22%5.4CVE-2025-63533Shridharshukl blood bank management system cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php and rprofile.php components. T…EPSS 0.22%5.4CVE-2025-63526Shridharshukl blood bank management system cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System within the abs.php component. The application fails to properly…EPSS 0.33%5.4CVE-2025-63527Shridharshukl blood bank management system cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php and hprofile.php components. T…EPSS 0.33%

Source: NIST National Vulnerability Database (record CVE-2025-63525), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.