VYPR

Client Management System

by Phpgurukul

CVEs (8)

  • CVE-2024-30990CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "searchdata" parameter.

  • CVE-2024-30985CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "todate" and "fromdate" parameters.

  • CVE-2024-48570HigOct 22, 2024
    risk 0.49cvss 7.5epss 0.01

    Client Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports parameter at /admin/bwdates-reports-ds.php.

  • CVE-2024-30988MedApr 17, 2024
    risk 0.44cvss 6.8epss 0.01

    Cross Site Scripting vulnerability in /search-invoices.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the Search bar.

  • CVE-2024-30987MedApr 17, 2024
    risk 0.44cvss 6.8epss 0.01

    Cross Site Scripting vulnerability in /bwdates-reports-ds.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the fromdate and todate parameters.

  • CVE-2024-30986MedApr 17, 2024
    risk 0.42cvss 6.5epss 0.00

    Cross Site Scripting vulnerability in /edit-services-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and via "price" and "sname" parameter.

  • CVE-2024-51209MedNov 20, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Scripting (XSS) vulnerabilities in Anuj Kumar's Client Management System Version 1.2 allow local attackers to inject arbitrary web script or HTML via the search input field parameter to admin search invoice page and client search invoice page.

  • CVE-2024-30989MedApr 17, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross Site Scripting vulnerability in /edit-client-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code via the "cname", "comname", "state" and "city" parameter.