CVE-2025-3195
Last modified
CVE-2025-3195 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability, which was classified as critical, has been found in itsourcecode Online Blood Bank Management System 1.0. This issue affects some unknown processing of the file /bbms.php. EPSS estimates a 0.48% chance of exploitation in the next 30 days.
Description
A vulnerability, which was classified as critical, has been found in itsourcecode Online Blood Bank Management System 1.0. This issue affects some unknown processing of the file /bbms.php. The manipulation of the argument Search leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adonesevangelista | Online Blood Bank Management System | 1.0 |
References
- https://github.com/p1026/CVE/issues/21Exploit, Issue Tracking, Third Party Advisory
- https://itsourcecode.com/Product
- https://vuldb.com/?ctiid.303149Permissions Required, VDB Entry
- https://vuldb.com/?id.303149Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.544147Third Party Advisory, VDB Entry
- https://github.com/p1026/CVE/issues/21Exploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-3195?
How severe is CVE-2025-3195?
How do I fix CVE-2025-3195?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-31944Race condition for some TDX Module before version tdx1.5 wit…5.6
- CVE-2025-31945An unauthenticated attacker can obtain other users' charger …6.9
- CVE-2025-31946Pixmeo OsiriX MD is vulnerable to a local use after free sc…6.9
- CVE-2025-31947Mattermost versions 10.6.x <= 10.6.1, 10.5.x <= 10.5.2, 10.4…5.3
- CVE-2025-31948Improper input validation for some Intel(R) oneAPI Math Kern…4.8
- CVE-2025-31949An authenticated attacker can obtain any plant name by knowi…5.3
- CVE-2025-31950An unauthenticated attacker can obtain EV charger energy con…6.9
- CVE-2025-31951HCL BigFix RunBookAI is affected by a Unvalidated Command In…8.8
- CVE-2025-31952HCL iAutomate is affected by an insufficient session expirat…7.1
- CVE-2025-31953HCL iAutomate includes hardcoded credentials which may resul…6.5
- CVE-2025-31954HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitiv…4.3
- CVE-2025-31955HCL iAutomate is affected by a sensitive data exposure vulne…6.5
Are you affected by CVE-2025-3195?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
