CVE-2025-63531CRITICAL 9.8EPSS p42.4%

CVE-2025-63531CVE-2025-63531

Description

A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properly sanitize user-supplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the remail and rpassword fields, an attacker can bypass authentication and gain unauthorized access to the system.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.56% probability of exploitation · percentile 42.4% · 2026-06-18T12:00:27Z
Published2025-12-01
Last modified2025-12-02

Underlying weaknesses· 1

CWE-89

References

  1. https://drive.google.com/file/d/12yeOXW_sN69QjsQtW0_k9AGqozi1s0di/view?usp=sharing
  2. https://github.com/Shridharshukl/Blood-Bank-Management-System
  3. https://github.com/kiwi865/CVEs/blob/main/CVE-2025-63531.md

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection')cwe-890%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-63535
CVE
CVE-2025-63532
CVE
CVE-2025-3307
CVE
CVE-2025-2391
CVE
CVE-2025-3309
CVE
CVE-2025-3306
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.