Description

A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's session identifier prior to authentication. When the victim logs in, the application continues to use the attacker-supplied session ID rather than generating a new one, enabling the attacker to hijack the authenticated session and gain unauthorized access to the victim's account.

INFO

Published Date :

2025-12-01T00:00:00.000Z

Last Modified :

2025-12-01T18:37:56.605Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-63529 vulnerability.

Vendors Products
Blood Bank Management System Project
  • Blood Bank Management System
Shridharshukl
  • Blood Bank Management System

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Complexity
Attack Vector
Availability Impact
Confidentiality Impact
Integrity Impact
Privileges Required
Scope
User Interaction