CVE-2024-12955

A vulnerability has been found in PHPGurukul Blood Bank & Donor Management System 2.4 and classified as problematic. This vulnerability affects unknown code of the file /logout.php. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://phpgurukul.com/ Product
https://vuldb.com/?ctiid.289318 Permissions Required VDB Entry
https://vuldb.com/?id.289318 Third Party Advisory VDB Entry
https://vuldb.com/?submit.468878 Third Party Advisory VDB Entry
https://vuldb.com/?submit.468878 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:phpgurukul:blood_bank_\&_donor_management_system:2.4:*:*:*:*:*:*:*

History

03 Apr 2025, 16:27

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad en PHPGurukul Blood Bank & Donor Management System 2.4 y se ha clasificado como problemática. Esta vulnerabilidad afecta al código desconocido del archivo /logout.php. La manipulación conduce a cross-site request forgery. El ataque puede iniciarse de forma remota. La vulnerabilidad se ha hecho pública y puede utilizarse.
First Time Phpgurukul
Phpgurukul blood Bank \& Donor Management System
CPE cpe:2.3:a:phpgurukul:blood_bank_\&_donor_management_system:2.4:*:*:*:*:*:*:*
References () https://phpgurukul.com/ - () https://phpgurukul.com/ - Product
References () https://vuldb.com/?ctiid.289318 - () https://vuldb.com/?ctiid.289318 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.289318 - () https://vuldb.com/?id.289318 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.468878 - () https://vuldb.com/?submit.468878 - Third Party Advisory, VDB Entry

26 Dec 2024, 16:15

Type Values Removed Values Added
References () https://vuldb.com/?submit.468878 - () https://vuldb.com/?submit.468878 -

26 Dec 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-26 15:15

Updated : 2025-04-03 16:27


NVD link : CVE-2024-12955

Mitre link : CVE-2024-12955

CVE.ORG link : CVE-2024-12955


JSON object : View

Products Affected

phpgurukul

  • blood_bank_\&_donor_management_system
CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-862

Missing Authorization