CVE-2025-50487
BaseFortify
Publication date: 2025-07-28
Last updated on: 2025-07-29
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| phpgurukul | blood_bank_\&_donor_management_system | 2.4 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-613 | According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization." |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an improper session invalidation issue in the /bbdms/change-password.php component of PHPGurukul Blood Bank & Donor Management System v2.4. It allows attackers to perform session hijacking attacks by exploiting the failure to properly invalidate user sessions after a password change.
How can this vulnerability impact me? :
An attacker could hijack a user's session, potentially gaining unauthorized access to the victim's account and sensitive information within the Blood Bank & Donor Management System. This could lead to data breaches, unauthorized actions, and compromise of user privacy.