VYPR

Online Library Management System

by Sourcecodester

CVEs (2)

  • CVE-2020-28130CriNov 17, 2020
    risk 0.64cvss 9.8epss 0.07

    An Arbitrary File Upload in the Upload Image component in SourceCodester Online Library Management System 1.0 allows the user to conduct remote code execution via admin/borrower/index.php?view=add because .php files can be uploaded to admin/borrower/photos (under the web root).

  • CVE-2026-4624HigMar 24, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in SourceCodester Online Library Management System 1.0. The impacted element is an unknown function of the file /home.php of the component Parameter Handler. Performing a manipulation of the argument searchField results in sql injection. The attack…