VYPR

Vendor CVEs

Kashipara

All CVEs

199 total · sorted by risk
  • CVE-2024-54934CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.

  • CVE-2024-54932CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.

  • CVE-2024-54931CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.

  • CVE-2024-54925CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.

  • CVE-2024-54924CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the title and content parameters.

  • CVE-2024-54923CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the department parameter.

  • CVE-2024-54921CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username, firstname, lastname, and class_id parameters.

  • CVE-2024-54918CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.

  • CVE-2024-54920CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the firstname, lastname, and class_id parameters.

  • CVE-2024-50823CriNov 14, 2024
    risk 0.64cvss 9.8epss 0.00

    A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.

  • CVE-2024-50833CriNov 14, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password parameters.

  • CVE-2024-42797CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music playlist entries.

  • CVE-2024-42765CriAug 23, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in "/login.php" of the Kashipara Bus Ticket Reservation System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the "email" or "password" Login page parameters.

  • CVE-2024-42784CriAug 21, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.

  • CVE-2024-42783CriAug 21, 2024
    risk 0.64cvss 9.8epss 0.00

    Kashipara Music Management System v1.0 is vulnerable to SQL Injection via /music/manage_playlist_items.php. An attacker can execute arbitrary SQL commands via the "pid" parameter.

  • CVE-2024-42782CriAug 21, 2024
    risk 0.64cvss 9.8epss 0.00

    A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "search" parameter.

  • CVE-2024-42781CriAug 21, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email parameter.

  • CVE-2024-42777CriAug 21, 2024
    risk 0.64cvss 9.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-40486CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email or password Login parameters.

  • CVE-2024-40482CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-40480CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam System v1.0, which allows remote unauthenticated attackers to view administrator dashboard and delete valid user accounts via the direct URL access.

  • CVE-2024-41237CriAug 7, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.

  • CVE-2023-50867CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the signupAction.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-50866CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginAction.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-50865CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'city' parameter of the hotelSearch.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-50864CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelId' parameter of the hotelDetails.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-50863CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the generateReceipt.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-50862CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the booking.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-50753CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the user/update_profile.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-50752CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'e' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-50743CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the registration.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49666CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'custmer_details' parameter of the submit_material_list.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49665CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'quantity[]' parameter of the submit_delivery_list.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49658CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'bank_details' parameter of the party_submit.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49639CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'customer_details' parameter of the buyer_invoice_submit.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49633CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'buyer_address' parameter of the buyer_detail_submit.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49625CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partylist_edit_submit.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49624CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cancelid' parameter of the material_bill.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49622CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'itemnameid' parameter of the material_bill.php?action=itemRelation resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49689CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'JobId' parameter of the Employer/DeleteJob.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49688CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txtUser' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49681CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cmbQual' parameter of the Employer/InsertWalkin.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49677CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cmbQual' parameter of the Employer/InsertJob.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2022-30810CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    elitecms v1.01 is vulnerable to SQL Injection via admin/edit_post.php.

  • CVE-2024-42764CriAug 23, 2024
    risk 0.61cvss 9.4epss 0.00

    Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php.

  • CVE-2025-51567CriJan 12, 2026
    risk 0.59cvss 9.1epss 0.00

    A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP…

  • CVE-2024-42773CriAug 22, 2024
    risk 0.59cvss 9.1epss 0.00

    An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to edit the valid hotel room entries in the administrator section.

  • CVE-2024-42775CriAug 22, 2024
    risk 0.59cvss 9.1epss 0.00

    An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room entries in the administrator section via the direct URL access.

  • CVE-2025-45322HigMay 5, 2025
    risk 0.57cvss 8.8epss 0.00

    kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the checkid parameter.

  • CVE-2025-45321HigMay 5, 2025
    risk 0.57cvss 8.8epss 0.00

    kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.php via the parameter: rPassword.

Page 1 of 4