VYPR

LAN Management System

by Lan Management System

CVEs (70)

  • CVE-2025-29454MedApr 17, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload function.

  • CVE-2022-29008MedMay 11, 2022
    risk 0.42cvss 6.5epss 0.01

    An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information.

  • CVE-2025-70890MedJan 15, 2026
    risk 0.40cvss 6.1epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in Cyber Cafe Management System v1.0. An authenticated attacker can inject arbitrary JavaScript code into the username parameter via the add-users.php endpoint. The injected payload is stored and executed in the victim s…

  • CVE-2024-31648MedApr 15, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter at /core/new_category2.

  • CVE-2023-49540MedMar 1, 2024
    risk 0.40cvss 6.1epss 0.01

    Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/history. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the history parameter.

  • CVE-2023-49539MedMar 1, 2024
    risk 0.40cvss 6.1epss 0.01

    Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/category. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the category parameter.

  • CVE-2023-23024MedJan 20, 2023
    risk 0.40cvss 6.1epss 0.00

    Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the writer parameter.

  • CVE-2022-46622MedJan 12, 2023
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in Judging Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter.

  • CVE-2022-45225MedNov 25, 2022
    risk 0.40cvss 6.1epss 0.00

    Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the book_title parameter.

  • CVE-2022-25575MedMar 24, 2022
    risk 0.40cvss 6.1epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Parking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via crafted payloads injected into the user name, password, and verification code text boxes.

  • CVE-2024-30979MedApr 17, 2024
    risk 0.38cvss 5.9epss 0.01

    Cross Site Scripting vulnerability in Cyber Cafe Management System 1.0 allows a remote attacker to execute arbitrary code via the compname parameter in edit-computer-details.php.

  • CVE-2022-41358MedOct 20, 2022
    risk 0.38cvss 5.4epss 0.03

    A stored cross-site scripting (XSS) vulnerability in Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php.

  • CVE-2022-45217MedDec 7, 2022
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Level parameter under the Add New System User module.

  • CVE-2022-45215MedDec 2, 2022
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the Add New System User module.

  • CVE-2021-41434MedSep 28, 2022
    risk 0.35cvss 5.4epss 0.01

    A stored Cross-Site Scripting (XSS) vulnerability exists in version 1.0 of the Expense Management System application that allows for arbitrary execution of JavaScript commands through index.php.

  • CVE-2022-36638MedSep 2, 2022
    risk 0.35cvss 5.3epss 0.01

    An access control issue in the component print.php of Garage Management System v1.0 allows unauthenticated attackers to access data for all existing orders.

  • CVE-2022-33075MedJul 5, 2022
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via unspecified vectors.

  • CVE-2023-38920MedNov 13, 2024
    risk 0.31cvss 4.8epss 0.00

    Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the adminname parameter.

  • CVE-2023-41614MedSep 21, 2023
    risk 0.31cvss 4.8epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Add Animal Details function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description of Animal parameter.

  • CVE-2023-37689MedAug 8, 2023
    risk 0.31cvss 4.8epss 0.00

    Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Booking Request page.