VYPR

College Management System

by Kashipara

CVEs (75)

  • CVE-2024-42797CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music playlist entries.

  • CVE-2024-42784CriAug 21, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.

  • CVE-2024-42783CriAug 21, 2024
    risk 0.64cvss 9.8epss 0.00

    Kashipara Music Management System v1.0 is vulnerable to SQL Injection via /music/manage_playlist_items.php. An attacker can execute arbitrary SQL commands via the "pid" parameter.

  • CVE-2024-42782CriAug 21, 2024
    risk 0.64cvss 9.8epss 0.00

    A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "search" parameter.

  • CVE-2024-42781CriAug 21, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email parameter.

  • CVE-2024-42777CriAug 21, 2024
    risk 0.64cvss 9.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2022-30810CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    elitecms v1.01 is vulnerable to SQL Injection via admin/edit_post.php.

  • CVE-2024-42773CriAug 22, 2024
    risk 0.59cvss 9.1epss 0.00

    An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to edit the valid hotel room entries in the administrator section.

  • CVE-2024-42775CriAug 22, 2024
    risk 0.59cvss 9.1epss 0.00

    An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the administrator section via the direct URL access.

  • CVE-2024-42791HigAug 26, 2024
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_genre.

  • CVE-2024-42786HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability in "/music/view_user.php" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter of View User Profile Page.

  • CVE-2024-42785HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability in /music/index.php?page=view_playlist in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.

  • CVE-2024-42780HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-42779HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-42778HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-42793HigAug 28, 2024
    risk 0.52cvss 8.0epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted request to the /music/ajax.php?action=save_user page.

  • CVE-2024-42798HigSep 16, 2024
    risk 0.49cvss 7.6epss 0.00

    An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Management System v1.0. This allows a low privileged attacker to take over the administrator account.

  • CVE-2024-42774HigAug 22, 2024
    risk 0.49cvss 7.5epss 0.00

    An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room entries in the administrator section.

  • CVE-2024-42772HigAug 22, 2024
    risk 0.49cvss 7.5epss 0.00

    An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room entries in administrator section.

  • CVE-2024-42767HigAug 22, 2024
    risk 0.47cvss 7.2epss 0.01

    Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.

Page 1 of 4