CVE-2026-5240 is a Cross-Site Scripting (XSS) vulnerability affecting code-projects BloodBank Managing System 1.0, specifically in the /admin_state.php file via manipulation of the 'statename' argument. Rated MEDIUM with a CVSS score of 4.3, this flaw allows for remote exploitation with low attack complexity, potentially leading to low integrity impact. Although publicly disclosed and mentioned in community discussions, there is currently no evidence of active exploitation or readily available exploit code in common repositories like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Code-Projects | BloodBank Managing System | 1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.