VYPR
Medium severity6.1NVD Advisory· Published Dec 1, 2025· Updated Jun 17, 2026

CVE-2025-63529

CVE-2025-63529

Description

A session fixation vulnerability exists in Blood Bank Management System 1.0 in login.php that allows an attacker to set or predict a user's session identifier prior to authentication. When the victim logs in, the application continues to use the attacker-supplied session ID rather than generating a new one, enabling the attacker to hijack the authenticated session and gain unauthorized access to the victim's account.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:shridharshukl:blood_bank_management_system:1.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:shridharshukl:blood_bank_management_system:1.0:*:*:*:*:*:*:*
    • (no CPE)range: <=1.0
  • Blood Bank Management System/Blood Bank Management Systemdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.