VYPR

Billing System Project

by Mayurik

CVEs (5)

  • CVE-2022-41504HigOct 18, 2022
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in the component /php_action/editProductImage.php of Billing System Project v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-41498HigOct 17, 2022
    risk 0.47cvss 7.2epss 0.01

    Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editbrand.php.

  • CVE-2022-41440HigSep 30, 2022
    risk 0.47cvss 7.2epss 0.01

    Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editcategory.php.

  • CVE-2022-41439HigSep 30, 2022
    risk 0.47cvss 7.2epss 0.01

    Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php.

  • CVE-2022-41437HigSep 30, 2022
    risk 0.47cvss 7.2epss 0.01

    Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/createProduct.php.