CWE Type: SQL Injection Component: Blood Bank Management System 1.0, receiverLogin.php CVE ID: CVE-2025-63531 Description: SQL injection vulnerability exists within the receiverLogin.php component due to improper sanitization of user-supplied input in SQL queries. An attacker can bypass authentication and gain unauthorized access by manipulating the remail and rpassword fields. Affected System: Blood Bank Management System Source: Shridharshukl/Blood-Bank-Management-System (GitHub) URLs: - Login Page: - Vulnerable File: - Profile Page: Exploitation Method: Use SQL syntax to bypass login, perform automated SQL injections, and manage full database and system access.