Junglewise Threat Intelligence

CVE-2026-10249: itsourcecode Online Blood Bank Management System SQL injection in viewrequest.php

CVE-2026-10249 · Severity: high · CVSS 7.3 · Published 2026-06-01

Vendors: Itsourcecode.

Executive brief

A security vulnerability exists in the Online Blood Bank Management System, a web application used to manage blood donor and request records. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive medical or personal information. This attack can be performed remotely without requiring any login credentials.

Technical details

A SQL injection vulnerability exists in itsourcecode Online Blood Bank Management System 1.0 within the /admin/viewrequest.php file. The application fails to properly validate or sanitize the 'id' GET parameter before using it in a database query. An unauthenticated remote attacker can exploit this by sending specially crafted SQL payloads (including boolean-based blind, error-based, and time-based blind techniques). Successful exploitation allows for unauthorized database access, data exfiltration, and potential modification of records. A public exploit (PoC) is available.

Affected products

  • itsourcecode Online Blood Bank Management System 1.0

Timeline

  • 2026-05-09: disclosed: Vulnerability reported on GitHub by zhengdexu-bot
  • 2026-06-01: advisory: CVE published and listed on VulDB/NVD

References

Related threats