vendor:
Blood Donor Management System
by:
Ehlullah Albayrak
5.5
CVSS
MEDIUM
Stored XSS
79
CWE
Product Name: Blood Donor Management System
Affected Version From: v1.0
Affected Version To: v1.0
Patch Exists: NO
Related CWE:
CPE: a:phpgurukul:blood_donor_management_system:1.0
Platforms Tested: Windows
2023
Blood Donor Management System v1.0 – Stored XSS
The Blood Donor Management System v1.0 is vulnerable to stored XSS. An attacker can inject malicious script in the 'State' input field, which will be executed when a user visits the welcome page.
Mitigation:
The vendor should sanitize user inputs to prevent XSS attacks. It is recommended to use input validation and output encoding techniques.