VYPR
Vendor

Alumni Management System Project

Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
  • CVE-2020-28070CriDec 23, 2020
    risk 0.66cvss 9.8epss 0.23

    SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via the 'id' parameter.

  • CVE-2021-25210CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to manage_event.php.

  • CVE-2020-29214CriJun 15, 2021
    risk 0.64cvss 9.8epss 0.04

    SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admin/login.php.

  • CVE-2020-28072HigDec 15, 2020
    risk 0.47cvss 7.2epss 0.03

    A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in the gallery.php page and executing it on the server reaching the RCE.

  • CVE-2020-28071MedDec 23, 2020
    risk 0.31cvss 4.8epss 0.01

    SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' and reach a stored XSS.