CVE-2022-38813
Summary
| CVE | CVE-2022-38813 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-25 17:15:00 UTC |
| Updated | 2022-11-29 21:22:00 UTC |
| Description | PHPGurukul Blood Donor Management System 1.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, delete the users, add and manage Blood Group, and Submit Report. |
Risk And Classification
Problem Types: CWE-668
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Phpgurukul Blood Donor Management System Project | Phpgurukul Blood Donor Management System | 1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Blood Donor Management System in CodeIgniter, Blood Donor Management Project | MISC | phpgurukul.com | |
| GitHub - RashidKhanPathan/CVE-2022-38813: Authenticated Vertical Privilege Escalation Vulnerability in Blood Donor Management System | MISC | github.com | |
| drive.google.com/file/d/1iMswKzoUvindXUGh1cuAmi-0R84tLDaH/view | MISC | drive.google.com | |
| CVE-2022-38813 Privilege Escalations in Blood Donor Management System Using CodeIgniter - 1.0 | MISC | ihexcoder.wixsite.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.