Simple Cold Storage Managment System
by Simple Cold Storage Management System Project
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-45253 | Cri | 0.64 | 9.8 | 0.01 | Dec 21, 2021 | The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The… | ||
| CVE-2022-43230 | Hig | 0.47 | 7.2 | 0.01 | Oct 28, 2022 | Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=bookings/view_details. | ||
| CVE-2022-43229 | Hig | 0.47 | 7.2 | 0.01 | Oct 28, 2022 | Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /bookings/update_status.php. | ||
| CVE-2022-42230 | Hig | 0.47 | 7.2 | 0.01 | Oct 11, 2022 | Simple Cold Storage Management System v1.0 is vulnerable to SQL Injection via /csms/admin/?page=user/manage_user&id=. |
- risk 0.64cvss 9.8epss 0.01
The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The…
- risk 0.47cvss 7.2epss 0.01
Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=bookings/view_details.
- risk 0.47cvss 7.2epss 0.01
Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /bookings/update_status.php.
- risk 0.47cvss 7.2epss 0.01
Simple Cold Storage Management System v1.0 is vulnerable to SQL Injection via /csms/admin/?page=user/manage_user&id=.