VYPR

Online Car Rental System

by Code Projects

CVEs (3)

  • CVE-2024-57487MedJan 13, 2025
    risk 0.45cvss 6.5epss 0.03

    In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a PHP shell without any restrictions and execute commands on the server.

  • CVE-2024-57488MedJan 13, 2025
    risk 0.42cvss 6.5epss 0.00

    Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter in /admin/edit-vehicle.php.

  • CVE-2024-12998MedDec 28, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, was found in code-projects Online Car Rental System 1.0. This affects an unknown part of the file /index.php of the component GET Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate…