HIGH · 8.1

CVE-2022-38813

PHPGurukul Blood Donor Management System 1.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, delete the users, add and manage Blood Group,...

Vulnerability Description

PHPGurukul Blood Donor Management System 1.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, delete the users, add and manage Blood Group, and Submit Report.

CVSS Score

8.1

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
Phpgurukul Blood Donor Management System ProjectPhpgurukul Blood Donor Management System1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-38813?

CVE-2022-38813 is a vulnerability with a CVSS score of 8.1 (HIGH). PHPGurukul Blood Donor Management System 1.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, delete the users, add and manage Blood Group,...

How severe is CVE-2022-38813?

CVE-2022-38813 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-38813?

Check the references section above for vendor advisories and patch information. Affected products include: Phpgurukul Blood Donor Management System Project Phpgurukul Blood Donor Management System.