Vendor CVEs
Code Projects
All CVEs
1,463 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-60302 | Med | 0.40 | 6.1 | 0.00 | Oct 9, 2025 | code-projects Client Details System 1.0 is vulnerable to Cross Site Scripting (XSS). When adding customer information, the client details system fills in malicious JavaScript code in the username field. | ||
| CVE-2025-40734 | Med | 0.40 | 6.1 | 0.00 | Jun 30, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the password and confirm_password parameters in /register.php. | ||
| CVE-2025-40733 | Med | 0.40 | 6.1 | 0.00 | Jun 30, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the username parameter in /login.php. | ||
| CVE-2025-46173 | Med | 0.40 | 6.1 | 0.00 | May 27, 2025 | code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) via the name field in the feedback form. | ||
| CVE-2025-29429 | Med | 0.40 | 6.1 | 0.00 | Mar 17, 2025 | Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/program.php via the id, code, and name parameters. | ||
| CVE-2024-50969 | Med | 0.40 | 6.1 | 0.01 | Nov 13, 2024 | A Reflected cross-site scripting (XSS) vulnerability in browse.php of Code-projects Jonnys Liquor 1.0 allows remote attackers to inject arbitrary web scripts or HTML via the search parameter. | ||
| CVE-2024-37800 | Med | 0.40 | 6.1 | 0.00 | Jun 18, 2024 | CodeProjects Restaurant Reservation System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Date parameter at index.php. | ||
| CVE-2024-34954 | Med | 0.40 | 6.1 | 0.00 | May 15, 2024 | Code-projects Budget Management 1.0 is vulnerable to Cross Site Scripting (XSS) via the budget parameter. | ||
| CVE-2023-42308 | Med | 0.40 | 6.1 | 0.00 | Mar 12, 2024 | Cross Site Scripting (XSS) vulnerability in Manage Fastrack Subjects in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via the "Subject Name" and "Subject Code" Section. | ||
| CVE-2023-42307 | Med | 0.40 | 6.1 | 0.00 | Mar 12, 2024 | Cross Site Scripting (XSS) vulnerability in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via "Subject Name" and "Subject Code" section. | ||
| CVE-2024-25226 | Med | 0.40 | 6.1 | 0.00 | Feb 14, 2024 | A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter under the Add Category function. | ||
| CVE-2024-25221 | Med | 0.40 | 6.1 | 0.00 | Feb 14, 2024 | A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Note Section parameter at /TaskManager/Tasks.php. | ||
| CVE-2024-25219 | Med | 0.40 | 6.1 | 0.00 | Feb 14, 2024 | A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Task Name parameter /TaskManager/Task.php. | ||
| CVE-2024-25218 | Med | 0.40 | 6.1 | 0.00 | Feb 14, 2024 | A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Project Name parameter /TaskManager/Projects.php. | ||
| CVE-2023-46020 | Med | 0.40 | 6.1 | 0.00 | Nov 13, 2023 | Cross Site Scripting (XSS) in updateprofile.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'rename', 'remail', 'rphone' and 'rcity' parameters. | ||
| CVE-2023-46019 | Med | 0.40 | 6.1 | 0.00 | Nov 13, 2023 | Cross Site Scripting (XSS) vulnerability in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'error' parameter. | ||
| CVE-2023-46016 | Med | 0.40 | 6.1 | 0.00 | Nov 13, 2023 | Cross Site Scripting (XSS) in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'search' parameter in the application URL. | ||
| CVE-2023-46015 | Med | 0.40 | 6.1 | 0.00 | Nov 13, 2023 | Cross Site Scripting (XSS) vulnerability in index.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via 'msg' parameter in application URL. | ||
| CVE-2023-42253 | Med | 0.40 | 6.1 | 0.00 | Sep 18, 2023 | Code-Projects Vehicle Management 1.0 is vulnerable to Cross Site Scripting (XSS) in Add Accounts via Invoice No, To, and Mammul. | ||
| CVE-2025-29427 | Med | 0.38 | 5.9 | 0.00 | Mar 17, 2025 | Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in profile.php via the member_first and member_last parameters. | ||
| CVE-2025-2589 | Med | 0.36 | 5.5 | 0.00 | Mar 21, 2025 | A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue affects the function Index of the file \handler\Account.go. The manipulation of the argument user_cookie leads to improper authorization. The exploit has been… | ||
| CVE-2025-29425 | Med | 0.36 | 5.5 | 0.00 | Mar 17, 2025 | Code-projects Online Class and Exam Scheduling System 1.0 is vulnerable to SQL Injection in exam_save.php via the parameters member and first. | ||
| CVE-2023-41015 | Med | 0.36 | 5.5 | 0.00 | Mar 7, 2024 | code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via /Employer/DeleteJob.php?JobId=1. | ||
| CVE-2024-1821 | Med | 0.36 | 5.5 | 0.01 | Feb 23, 2024 | A vulnerability was found in code-projects Crime Reporting System 1.0. It has been rated as critical. This issue affects some unknown processing of the file police_add.php. The manipulation of the argument police_name/police_id/police_spec/password leads to sql injection. The… | ||
| CVE-2024-0466 | Med | 0.36 | 5.5 | 0.01 | Jan 12, 2024 | A vulnerability, which was classified as critical, has been found in code-projects Employee Profile Management System 1.0. This issue affects some unknown processing of the file file_table.php. The manipulation of the argument per_id leads to sql injection. The exploit has been… | ||
| CVE-2023-7129 | Med | 0.36 | 5.5 | 0.01 | Dec 28, 2023 | A vulnerability, which was classified as critical, was found in code-projects Voting System 1.0. Affected is an unknown function of the component Voters Login. The manipulation of the argument voter leads to sql injection. The exploit has been disclosed to the public and may be… | ||
| CVE-2023-46581 | Med | 0.36 | 5.5 | 0.00 | Nov 14, 2023 | SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary code via the name, uname and email parameters in the registration.php component. | ||
| CVE-2023-46021 | Med | 0.36 | 5.5 | 0.00 | Nov 13, 2023 | SQL Injection vulnerability in cancel.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary commands via the 'reqid' parameter. | ||
| CVE-2023-46018 | Med | 0.36 | 5.5 | 0.00 | Nov 13, 2023 | SQL injection vulnerability in receiverReg.php in Code-Projects Blood Bank 1.0 \allows attackers to run arbitrary SQL commands via 'remail' parameter. | ||
| CVE-2023-46017 | Med | 0.36 | 5.5 | 0.00 | Nov 13, 2023 | SQL Injection vulnerability in receiverLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'remail' and 'rpassword' parameters. | ||
| CVE-2023-46014 | Med | 0.36 | 5.5 | 0.00 | Nov 13, 2023 | SQL Injection vulnerability in hospitalLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'hemail' and 'hpassword' parameters. | ||
| CVE-2026-7631 | Med | 0.35 | 5.4 | 0.00 | May 2, 2026 | A vulnerability was found in code-projects Online Hospital Management System 1.0. The impacted element is an unknown function of the component Registration Handler. The manipulation of the argument Username results in improper authorization. The attack can be executed remotely.… | ||
| CVE-2025-56293 | Med | 0.35 | 5.4 | 0.00 | Sep 16, 2025 | code-projects Human Resource Integrated System 1.0 is vulnerable to Cross Site Scripting (XSS) in the Add Child Information section in the Childs Name field. | ||
| CVE-2025-56289 | Med | 0.35 | 5.4 | 0.00 | Sep 16, 2025 | code-projects Document Management System 1.0 has a Cross Site Scripting (XSS) vulnerability, where attackers can leak admin's cookie information by entering malicious XSS code in the Company field when adding files. | ||
| CVE-2025-56280 | Med | 0.35 | 5.4 | 0.00 | Sep 16, 2025 | code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the area where users submit reservation information. | ||
| CVE-2025-56276 | Med | 0.35 | 5.4 | 0.00 | Sep 16, 2025 | code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the registration function. An attacker enters malicious JavaScript code as a username, which triggers the XSS vulnerability when the admin views user information, resulting in the… | ||
| CVE-2025-8433 | Med | 0.35 | 5.4 | 0.00 | Aug 1, 2025 | A vulnerability was found in code-projects Document Management System 1.0 and classified as critical. This issue affects the function unlink of the file /dell.php. The manipulation of the argument ID leads to path traversal. The attack may be initiated remotely. The exploit has… | ||
| CVE-2024-37803 | Med | 0.35 | 5.4 | 0.00 | Jun 18, 2024 | Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname and lname parameters under the Staff Info page. | ||
| CVE-2024-37799 | Med | 0.35 | 5.4 | 0.00 | Jun 18, 2024 | CodeProjects Restaurant Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the reserv_id parameter at view_reservations.php. | ||
| CVE-2024-24097 | Med | 0.35 | 5.4 | 0.00 | Mar 12, 2024 | Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via the News Feed. | ||
| CVE-2024-24099 | Med | 0.35 | 5.4 | 0.00 | Feb 27, 2024 | Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update. | ||
| CVE-2024-25225 | Med | 0.35 | 5.4 | 0.00 | Feb 14, 2024 | A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter under the Add Category function. | ||
| CVE-2024-25224 | Med | 0.35 | 5.4 | 0.00 | Feb 14, 2024 | A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Size Number parameter under the Add Size function. | ||
| CVE-2023-46580 | Med | 0.35 | 5.4 | 0.01 | Nov 14, 2023 | Cross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the pname parameter of the editProduct.php component. | ||
| CVE-2022-40348 | Med | 0.35 | 5.4 | 0.01 | Feb 18, 2023 | Cross Site Scripting (XSS) vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'name' and 'email' parameters, allows attackers to execute arbitrary code. | ||
| CVE-2026-7132 | Med | 0.34 | 5.3 | 0.00 | Apr 27, 2026 | A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile of the file /download.php. The manipulation of the argument File results in path traversal. It is possible to launch the attack remotely. The exploit has been… | ||
| CVE-2026-7109 | Med | 0.34 | 5.3 | 0.00 | Apr 27, 2026 | A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /item of the component API Endpoint. Performing a manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit… | ||
| CVE-2026-6160 | Med | 0.34 | 5.3 | 0.00 | Apr 13, 2026 | A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP of the file chatbox.sql of the component Endpoint. Performing a manipulation results in file and directory information exposure. It is possible to initiate the… | ||
| CVE-2026-5666 | Med | 0.34 | 5.3 | 0.00 | Apr 6, 2026 | A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionality of the file /complaints.sql of the component SQL Database Backup File Handler. The manipulation results in insecure storage of sensitive information. The… | ||
| CVE-2026-5650 | Med | 0.34 | 5.3 | 0.00 | Apr 6, 2026 | A vulnerability was found in code-projects Online Application System for Admission 1.0. Impacted is an unknown function of the file /enrollment/database/oas.sql. Performing a manipulation results in insecure storage of sensitive information. The attack is possible to be carried… |
- risk 0.40cvss 6.1epss 0.00
code-projects Client Details System 1.0 is vulnerable to Cross Site Scripting (XSS). When adding customer information, the client details system fills in malicious JavaScript code in the username field.
- risk 0.40cvss 6.1epss 0.00
Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the password and confirm_password parameters in /register.php.
- risk 0.40cvss 6.1epss 0.00
Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the username parameter in /login.php.
- risk 0.40cvss 6.1epss 0.00
code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) via the name field in the feedback form.
- risk 0.40cvss 6.1epss 0.00
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/program.php via the id, code, and name parameters.
- risk 0.40cvss 6.1epss 0.01
A Reflected cross-site scripting (XSS) vulnerability in browse.php of Code-projects Jonnys Liquor 1.0 allows remote attackers to inject arbitrary web scripts or HTML via the search parameter.
- risk 0.40cvss 6.1epss 0.00
CodeProjects Restaurant Reservation System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Date parameter at index.php.
- risk 0.40cvss 6.1epss 0.00
Code-projects Budget Management 1.0 is vulnerable to Cross Site Scripting (XSS) via the budget parameter.
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting (XSS) vulnerability in Manage Fastrack Subjects in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via the "Subject Name" and "Subject Code" Section.
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting (XSS) vulnerability in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via "Subject Name" and "Subject Code" section.
- risk 0.40cvss 6.1epss 0.00
A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter under the Add Category function.
- risk 0.40cvss 6.1epss 0.00
A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Note Section parameter at /TaskManager/Tasks.php.
- risk 0.40cvss 6.1epss 0.00
A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Task Name parameter /TaskManager/Task.php.
- risk 0.40cvss 6.1epss 0.00
A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Project Name parameter /TaskManager/Projects.php.
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting (XSS) in updateprofile.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'rename', 'remail', 'rphone' and 'rcity' parameters.
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting (XSS) vulnerability in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'error' parameter.
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting (XSS) in abs.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via the 'search' parameter in the application URL.
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting (XSS) vulnerability in index.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary code via 'msg' parameter in application URL.
- risk 0.40cvss 6.1epss 0.00
Code-Projects Vehicle Management 1.0 is vulnerable to Cross Site Scripting (XSS) in Add Accounts via Invoice No, To, and Mammul.
- risk 0.38cvss 5.9epss 0.00
Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in profile.php via the member_first and member_last parameters.
- risk 0.36cvss 5.5epss 0.00
A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue affects the function Index of the file \handler\Account.go. The manipulation of the argument user_cookie leads to improper authorization. The exploit has been…
- risk 0.36cvss 5.5epss 0.00
Code-projects Online Class and Exam Scheduling System 1.0 is vulnerable to SQL Injection in exam_save.php via the parameters member and first.
- risk 0.36cvss 5.5epss 0.00
code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via /Employer/DeleteJob.php?JobId=1.
- risk 0.36cvss 5.5epss 0.01
A vulnerability was found in code-projects Crime Reporting System 1.0. It has been rated as critical. This issue affects some unknown processing of the file police_add.php. The manipulation of the argument police_name/police_id/police_spec/password leads to sql injection. The…
- risk 0.36cvss 5.5epss 0.01
A vulnerability, which was classified as critical, has been found in code-projects Employee Profile Management System 1.0. This issue affects some unknown processing of the file file_table.php. The manipulation of the argument per_id leads to sql injection. The exploit has been…
- risk 0.36cvss 5.5epss 0.01
A vulnerability, which was classified as critical, was found in code-projects Voting System 1.0. Affected is an unknown function of the component Voters Login. The manipulation of the argument voter leads to sql injection. The exploit has been disclosed to the public and may be…
- risk 0.36cvss 5.5epss 0.00
SQL injection vulnerability in Inventory Management v.1.0 allows a local attacker to execute arbitrary code via the name, uname and email parameters in the registration.php component.
- risk 0.36cvss 5.5epss 0.00
SQL Injection vulnerability in cancel.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary commands via the 'reqid' parameter.
- risk 0.36cvss 5.5epss 0.00
SQL injection vulnerability in receiverReg.php in Code-Projects Blood Bank 1.0 \allows attackers to run arbitrary SQL commands via 'remail' parameter.
- risk 0.36cvss 5.5epss 0.00
SQL Injection vulnerability in receiverLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'remail' and 'rpassword' parameters.
- risk 0.36cvss 5.5epss 0.00
SQL Injection vulnerability in hospitalLogin.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via 'hemail' and 'hpassword' parameters.
- risk 0.35cvss 5.4epss 0.00
A vulnerability was found in code-projects Online Hospital Management System 1.0. The impacted element is an unknown function of the component Registration Handler. The manipulation of the argument Username results in improper authorization. The attack can be executed remotely.…
- risk 0.35cvss 5.4epss 0.00
code-projects Human Resource Integrated System 1.0 is vulnerable to Cross Site Scripting (XSS) in the Add Child Information section in the Childs Name field.
- risk 0.35cvss 5.4epss 0.00
code-projects Document Management System 1.0 has a Cross Site Scripting (XSS) vulnerability, where attackers can leak admin's cookie information by entering malicious XSS code in the Company field when adding files.
- risk 0.35cvss 5.4epss 0.00
code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the area where users submit reservation information.
- risk 0.35cvss 5.4epss 0.00
code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the registration function. An attacker enters malicious JavaScript code as a username, which triggers the XSS vulnerability when the admin views user information, resulting in the…
- risk 0.35cvss 5.4epss 0.00
A vulnerability was found in code-projects Document Management System 1.0 and classified as critical. This issue affects the function unlink of the file /dell.php. The manipulation of the argument ID leads to path traversal. The attack may be initiated remotely. The exploit has…
- risk 0.35cvss 5.4epss 0.00
Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname and lname parameters under the Staff Info page.
- risk 0.35cvss 5.4epss 0.00
CodeProjects Restaurant Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the reserv_id parameter at view_reservations.php.
- risk 0.35cvss 5.4epss 0.00
Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via the News Feed.
- risk 0.35cvss 5.4epss 0.00
Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update.
- risk 0.35cvss 5.4epss 0.00
A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter under the Add Category function.
- risk 0.35cvss 5.4epss 0.00
A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Size Number parameter under the Add Size function.
- risk 0.35cvss 5.4epss 0.01
Cross-Site Scripting (XSS) vulnerability in Inventory Management V1.0 allows attackers to execute arbitrary code via the pname parameter of the editProduct.php component.
- risk 0.35cvss 5.4epss 0.01
Cross Site Scripting (XSS) vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'name' and 'email' parameters, allows attackers to execute arbitrary code.
- risk 0.34cvss 5.3epss 0.00
A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile of the file /download.php. The manipulation of the argument File results in path traversal. It is possible to launch the attack remotely. The exploit has been…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /item of the component API Endpoint. Performing a manipulation results in improper authorization. It is possible to initiate the attack remotely. The exploit…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP of the file chatbox.sql of the component Endpoint. Performing a manipulation results in file and directory information exposure. It is possible to initiate the…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionality of the file /complaints.sql of the component SQL Database Backup File Handler. The manipulation results in insecure storage of sensitive information. The…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was found in code-projects Online Application System for Admission 1.0. Impacted is an unknown function of the file /enrollment/database/oas.sql. Performing a manipulation results in insecure storage of sensitive information. The attack is possible to be carried…
Page 22 of 30