A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's session identifier prior to authentication. When the victim logs in, the application continues to use the attacker-supplied session ID rather than generating a new one, enabling the attacker to hijack the authenticated session and gain unauthorized access to the victim's account.
References
| Link | Resource |
|---|---|
| https://drive.google.com/file/d/12yeOXW_sN69QjsQtW0_k9AGqozi1s0di/view?usp=sharing | Exploit Third Party Advisory |
| https://github.com/Shridharshukl/Blood-Bank-Management-System | Product |
| https://github.com/kiwi865/CVEs/blob/main/CVE-2025-63529.md | Exploit |
Configurations
History
02 Dec 2025, 03:04
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:shridharshukl:blood_bank_management_system:1.0:*:*:*:*:*:*:* | |
| First Time |
Shridharshukl blood Bank Management System
Shridharshukl |
|
| References | () https://drive.google.com/file/d/12yeOXW_sN69QjsQtW0_k9AGqozi1s0di/view?usp=sharing - Exploit, Third Party Advisory | |
| References | () https://github.com/Shridharshukl/Blood-Bank-Management-System - Product | |
| References | () https://github.com/kiwi865/CVEs/blob/main/CVE-2025-63529.md - Exploit |
01 Dec 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-384 |
01 Dec 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-01 15:15
Updated : 2025-12-02 03:04
NVD link : CVE-2025-63529
Mitre link : CVE-2025-63529
CVE.ORG link : CVE-2025-63529
JSON object : View
Products Affected
shridharshukl
- blood_bank_management_system
CWE
CWE-384
Session Fixation
