Automotive Shop Management System
by Automotive Shop Management System Project
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-30495 | Cri | 0.64 | 9.8 | 0.01 | May 26, 2022 | In oretnom23 Automotive Shop Management System v1.0, the name id parameter is vulnerable to IDOR - Broken Access Control allowing attackers to change the admin password(vertical privilege escalation) | ||
| CVE-2022-30493 | Cri | 0.64 | 9.8 | 0.02 | May 26, 2022 | In oretnom23 Automotive Shop Management System v1.0, the product id parameter suffers from a blind SQL Injection Vulnerability allowing remote attackers to dump all database credential and gain admin access(privilege escalation). | ||
| CVE-2022-44859 | Hig | 0.47 | 7.2 | 0.01 | Nov 25, 2022 | Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/admin/products/manage_product.php. | ||
| CVE-2022-44379 | Hig | 0.47 | 7.2 | 0.01 | Nov 18, 2022 | Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_service. | ||
| CVE-2022-30494 | Med | 0.35 | 5.4 | 0.01 | May 26, 2022 | In oretnom23 Automotive Shop Management System v1.0, the first and last name user fields suffer from a stored XSS Injection Vulnerability allowing remote attackers to gain admin access and view internal IPs. | ||
| CVE-2022-30458 | Med | 0.35 | 5.4 | 0.00 | May 24, 2022 | Automotive Shop Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /asms/classes/Master.php?f=save_product, name. |
- risk 0.64cvss 9.8epss 0.01
In oretnom23 Automotive Shop Management System v1.0, the name id parameter is vulnerable to IDOR - Broken Access Control allowing attackers to change the admin password(vertical privilege escalation)
- risk 0.64cvss 9.8epss 0.02
In oretnom23 Automotive Shop Management System v1.0, the product id parameter suffers from a blind SQL Injection Vulnerability allowing remote attackers to dump all database credential and gain admin access(privilege escalation).
- risk 0.47cvss 7.2epss 0.01
Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/admin/products/manage_product.php.
- risk 0.47cvss 7.2epss 0.01
Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_service.
- risk 0.35cvss 5.4epss 0.01
In oretnom23 Automotive Shop Management System v1.0, the first and last name user fields suffer from a stored XSS Injection Vulnerability allowing remote attackers to gain admin access and view internal IPs.
- risk 0.35cvss 5.4epss 0.00
Automotive Shop Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /asms/classes/Master.php?f=save_product, name.