← Vulnerability feed

Vulnerability record · CVE-2025-63529 · published 1 December 2025

CVE-2025-63529: Shridharshukl blood bank management system vulnerability

SShridharshukl · Blood Bank Management System

A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's session identifier prior to authentication. When the victim logs in, the application continues to use the attacker-supplied session ID rather than generating a new one, enabling the attacker to hijack the authenticated session and gain unauthorized access to the victim's account.

8.8 CVSS 3.1 High EPSS 0.37% · top 71.5% CWE-384 · CWE-384
8.8CVSS 3.1 base score
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's session identifier prior to authentication. When the victim logs in, the application continues to use the attacker-supplied session ID rather than generating a new one, enabling the attacker to hijack the authenticated session and gain unauthorized access to the victim's account.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-63529 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-63531Shridharshukl blood bank management system sql injection vulnerabilityA SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properl…EPSS 0.65%8.8CVE-2025-63535Shridharshukl blood bank management system sql injection vulnerabilityA SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The application fails to properly sanitize…EPSS 0.39%8.8CVE-2025-63532Shridharshukl blood bank management system sql injection vulnerabilityA SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The application fails to properly sanit…EPSS 0.39%8.8CVE-2025-63525Shridharshukl blood bank management system improper access control vulnerabilityAn issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted…EPSS 0.49%5.4CVE-2025-63534Shridharshukl blood bank management system cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the login.php component. The application fails to pr…EPSS 0.22%5.4CVE-2025-63533Shridharshukl blood bank management system cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php and rprofile.php components. T…EPSS 0.22%5.4CVE-2025-63526Shridharshukl blood bank management system cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System within the abs.php component. The application fails to properly…EPSS 0.33%5.4CVE-2025-63527Shridharshukl blood bank management system cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1.0 within the updateprofile.php and hprofile.php components. T…EPSS 0.33%

Source: NIST National Vulnerability Database (record CVE-2025-63529), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.