LAN Management System
CVEs (70)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-44755 | Cri | 0.64 | 9.8 | 0.01 | Apr 22, 2025 | Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacco/ajax.php. | ||
| CVE-2024-28613 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2024 | SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obtain sensitive information via the task_id parameter of the task-details.php, and edit-task.php component. | ||
| CVE-2023-49543 | Cri | 0.64 | 9.8 | 0.01 | Mar 1, 2024 | Incorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute administrative functions without authenticating. | ||
| CVE-2023-51951 | Cri | 0.64 | 9.8 | 0.01 | Feb 5, 2024 | SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id parameter in the manage_bo.php file. | ||
| CVE-2023-30245 | Cri | 0.64 | 9.8 | 0.01 | May 15, 2023 | SQL injection vulnerability found in Judging Management System v.1.0 allows a remote attacker to execute arbitrary code via the crit_id parameter of the edit_criteria.php file. | ||
| CVE-2023-30018 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2023 | Judging Management System v1.0 is vulnerable to SQL Injection. via /php-jms/review_se_result.php?mainevent_id=. | ||
| CVE-2023-24643 | Cri | 0.64 | 9.8 | 0.01 | Mar 3, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateBlankTxtview.php. | ||
| CVE-2023-24642 | Cri | 0.64 | 9.8 | 0.01 | Mar 3, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateTxtview.php. | ||
| CVE-2023-24641 | Cri | 0.64 | 9.8 | 0.01 | Mar 3, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateview.php. | ||
| CVE-2023-23279 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php. | ||
| CVE-2022-35156 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2022 | Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php.. | ||
| CVE-2022-34023 | Cri | 0.64 | 9.8 | 0.01 | Jul 19, 2022 | Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /officials/officials.php. | ||
| CVE-2022-30370 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo_type. | ||
| CVE-2022-29656 | Cri | 0.64 | 9.8 | 0.01 | May 11, 2022 | Wedding Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Wedding-Management/package_detail.php. | ||
| CVE-2020-23621 | Cri | 0.64 | 9.8 | 0.02 | May 2, 2022 | The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object. | ||
| CVE-2021-45003 | Cri | 0.64 | 9.8 | 0.03 | Jan 10, 2022 | Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.php through the "image" parameter that can execute a webshell payload. | ||
| CVE-2024-48594 | Hig | 0.60 | 8.8 | 0.03 | Oct 28, 2024 | File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the file upload component. | ||
| CVE-2023-53734 | Hig | 0.57 | — | 0.01 | Dec 4, 2025 | dawa-pharma-1.0 allows unauthenticated attackers to execute SQL queries on the server, allowing them to access sensitive information and potentially gain administrative access. | ||
| CVE-2020-36073 | Hig | 0.57 | 8.8 | 0.01 | Apr 6, 2023 | SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via the detail parameter of the document.php page. | ||
| CVE-2020-36072 | Hig | 0.57 | 8.8 | 0.01 | Apr 6, 2023 | SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via the id parameter. |
- risk 0.64cvss 9.8epss 0.01
Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacco/ajax.php.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obtain sensitive information via the task_id parameter of the task-details.php, and edit-task.php component.
- risk 0.64cvss 9.8epss 0.01
Incorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute administrative functions without authenticating.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id parameter in the manage_bo.php file.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability found in Judging Management System v.1.0 allows a remote attacker to execute arbitrary code via the crit_id parameter of the edit_criteria.php file.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 is vulnerable to SQL Injection. via /php-jms/review_se_result.php?mainevent_id=.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateBlankTxtview.php.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateTxtview.php.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateview.php.
- risk 0.64cvss 9.8epss 0.01
Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php.
- risk 0.64cvss 9.8epss 0.01
Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..
- risk 0.64cvss 9.8epss 0.01
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /officials/officials.php.
- risk 0.64cvss 9.8epss 0.01
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo_type.
- risk 0.64cvss 9.8epss 0.01
Wedding Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Wedding-Management/package_detail.php.
- risk 0.64cvss 9.8epss 0.02
The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.
- risk 0.64cvss 9.8epss 0.03
Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.php through the "image" parameter that can execute a webshell payload.
- risk 0.60cvss 8.8epss 0.03
File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the file upload component.
- risk 0.57cvss —epss 0.01
dawa-pharma-1.0 allows unauthenticated attackers to execute SQL queries on the server, allowing them to access sensitive information and potentially gain administrative access.
- risk 0.57cvss 8.8epss 0.01
SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via the detail parameter of the document.php page.
- risk 0.57cvss 8.8epss 0.01
SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via the id parameter.
Page 1 of 4