VYPR

Beauty-Parlour-Management-System

by BigTiger2020

CVEs (2)

  • CVE-2021-27545MedApr 15, 2021
    risk 0.42cvss 6.5epss 0.02

    SQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to obtain sensitive database information by injecting SQL commands into the "sername" parameter.

  • CVE-2021-27544MedApr 15, 2021
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "sername" parameter.