VYPR

School Event Management System

by Janobe

CVEs (13)

  • CVE-2024-33994HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in '/event/index.php'.

  • CVE-2024-33993HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in /candidate/index.php'.

  • CVE-2024-33992HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in…

  • CVE-2024-33991HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in…

  • CVE-2024-33990HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via the 'id'…

  • CVE-2024-33989HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload to an authenticated user and partially take over their browser session via…

  • CVE-2024-33988HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance',…

  • CVE-2024-33987HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance',…

  • CVE-2024-33986HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter…

  • CVE-2024-33985HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter…

  • CVE-2024-33984HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance',…

  • CVE-2024-33983HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'Attendance',…

  • CVE-2024-33982HigAug 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'StudentID'…