A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's session identifier prior to authentication. When the victim logs in, the application continues to use the attacker-supplied session ID rather than generating a new one, enabling the attacker to hijack the authenticated session and gain unauthorized access to the victim's account.
References
| Link | Resource |
|---|---|
| https://drive.google.com/file/d/12yeOXW_sN69QjsQtW0_k9AGqozi1s0di/view?usp=sharing | Exploit Third Party Advisory |
| https://github.com/Shridharshukl/Blood-Bank-Management-System | Product |
| https://github.com/kiwi865/CVEs/blob/main/CVE-2025-63529.md | Exploit |
Configurations
History
No history.
Information
Published : 2025-12-01 15:15
Updated : 2025-12-02 03:04
NVD link : CVE-2025-63529
Mitre link : CVE-2025-63529
CVE.ORG link : CVE-2025-63529
JSON object : View
Products Affected
shridharshukl
- blood_bank_management_system
CWE
CWE-384
Session Fixation
