Simple School Management System
CVEs (9)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-25310 | Hig | 0.57 | 8.8 | 0.01 | Feb 9, 2024 | Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5." | ||
| CVE-2024-25313 | Hig | 0.57 | 8.8 | 0.01 | Feb 9, 2024 | Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/teacher_login.php. | ||
| CVE-2024-25312 | Hig | 0.57 | 8.8 | 0.01 | Feb 9, 2024 | Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?id=5." | ||
| CVE-2024-25309 | Hig | 0.57 | 8.8 | 0.01 | Feb 9, 2024 | Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.php. | ||
| CVE-2024-25308 | Hig | 0.57 | 8.8 | 0.01 | Feb 9, 2024 | Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.php. | ||
| CVE-2024-25306 | Hig | 0.57 | 8.8 | 0.01 | Feb 9, 2024 | Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'aname' parameter at "School/index.php". | ||
| CVE-2024-25305 | Hig | 0.57 | 8.8 | 0.01 | Feb 9, 2024 | Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/index.php. | ||
| CVE-2024-25304 | Hig | 0.57 | 8.8 | 0.01 | Feb 9, 2024 | Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'apass' parameter at "School/index.php." | ||
| CVE-2024-31610 | Med | 0.41 | 6.3 | 0.00 | Apr 25, 2024 | File Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management System v1.0 allows attackers to run arbitrary code via upload of crafted file. |
- risk 0.57cvss 8.8epss 0.01
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5."
- risk 0.57cvss 8.8epss 0.01
Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/teacher_login.php.
- risk 0.57cvss 8.8epss 0.01
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?id=5."
- risk 0.57cvss 8.8epss 0.01
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.php.
- risk 0.57cvss 8.8epss 0.01
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.php.
- risk 0.57cvss 8.8epss 0.01
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'aname' parameter at "School/index.php".
- risk 0.57cvss 8.8epss 0.01
Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/index.php.
- risk 0.57cvss 8.8epss 0.01
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'apass' parameter at "School/index.php."
- risk 0.41cvss 6.3epss 0.00
File Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management System v1.0 allows attackers to run arbitrary code via upload of crafted file.