VYPR

Casap Automated Enrollment System

by Casap Automated Enrollment System Project

CVEs (7)

  • CVE-2021-26229CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_stud.php.

  • CVE-2021-26201CriFeb 15, 2021
    risk 0.64cvss 9.8epss 0.02

    The Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authentication bypass. An attacker can obtain access to the admin panel by injecting a SQL query in the username field of the login page.

  • CVE-2021-40261MedNov 8, 2021
    risk 0.40cvss 6.1epss 0.01

    Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester CASAP Automated Enrollment System 1.0 via the (1) user_username and (2) category parameters in save_class.php, the (3) firstname, (4) class, and (5) status parameters in student_table.php, the (6)…

  • CVE-2021-26230MedJul 22, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the user information to save_user.php.

  • CVE-2021-26227MedJul 22, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the student information parameters to edit_stud.php.

  • CVE-2021-3294MedFeb 9, 2021
    risk 0.38cvss 5.4epss 0.03

    CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a cookie to perform user redirection to a malicious website.

  • CVE-2021-27129MedApr 15, 2021
    risk 0.35cvss 5.4epss 0.01

    CASAP Automated Enrollment System version 1.0 contains a cross-site scripting (XSS) vulnerability through the Students > Edit > ROUTE parameter.