PHPGurukul Blood Donor Management System 1.0 does not...
High severity
Unreviewed
Published
Nov 25, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Nov 25, 2022
Published to the GitHub Advisory Database
Nov 25, 2022
Last updated
Feb 1, 2023
PHPGurukul Blood Donor Management System 1.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, delete the users, add and manage Blood Group, and Submit Report.
References