CVE-2025-11481 - CVE House
Back to Database
Status published Medium CVE-2025-11481

varunsardana004 Blood-Bank-And-Donation-Management-System donate_blood.php sql injection

Vulnerability Description

A flaw has been found in varunsardana004 Blood-Bank-And-Donation-Management-System up to dc9e0393d826fbc85fad9755b5bc12cba1919df2. The impacted element is an unknown function of the file /donate_blood.php. Executing manipulation of the argument fullname can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11481

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • redteam_bd (VulDB User)

Affected Vendor

varunsardana004

View all reports →

Affected Software

Blood-Bank-And-Donation-Management-System
Vulnerable Versions:
dc9e0393d826fbc85fad9755b5bc12cba1919df2

Timeline

Official Publish: October 8th, 2025
Last Modified: October 8th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R

Weaknesses (CWE)