VYPR

Vendor CVEs

Kashipara

All CVEs

199 total · sorted by risk
  • CVE-2024-54926HigDec 9, 2024
    risk 0.57cvss 8.8epss 0.01

    A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the school_year parameter.

  • CVE-2024-42791HigAug 26, 2024
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_genre.

  • CVE-2024-42786HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability in "/music/view_user.php" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter of View User Profile Page.

  • CVE-2024-42785HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability in /music/index.php?page=view_playlist in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.

  • CVE-2024-42780HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-42779HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-42778HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-40488HigAug 12, 2024
    risk 0.57cvss 8.8epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the administrator into deleting valid member data via a crafted HTML page, as demonstrated by a Delete Member action at the…

  • CVE-2023-50760HigJan 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Online Notice Board System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'f' parameter of user/update_profile_pic.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

  • CVE-2023-5011HigDec 20, 2023
    risk 0.57cvss 8.8epss 0.01

    Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'coursename' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-5010HigDec 20, 2023
    risk 0.57cvss 8.8epss 0.01

    Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'coursecode' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-5007HigDec 20, 2023
    risk 0.57cvss 8.8epss 0.01

    Student Information System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'id' parameter of the marks.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2024-40479HigAug 12, 2024
    risk 0.53cvss 8.1epss 0.01

    A SQL injection vulnerability in "/admin/quizquestion.php" in Kashipara Online Exam System v1.0 allows remote attackers to execute arbitrary SQL commands via the "eid" parameter.

  • CVE-2024-42793HigAug 28, 2024
    risk 0.52cvss 8.0epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted request to the /music/ajax.php?action=save_user page.

  • CVE-2024-54938HigDec 9, 2024
    risk 0.49cvss 7.5epss 0.01

    A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads.

  • CVE-2024-42798HigSep 16, 2024
    risk 0.49cvss 7.6epss 0.00

    An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Management System v1.0. This allows a low privileged attacker to take over the administrator account.

  • CVE-2024-42774HigAug 22, 2024
    risk 0.49cvss 7.5epss 0.00

    An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room entries in the administrator section.

  • CVE-2024-42772HigAug 22, 2024
    risk 0.49cvss 7.5epss 0.00

    An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room entries in administrator section.

  • CVE-2024-40487HigAug 12, 2024
    risk 0.49cvss 7.6epss 0.01

    A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0, which allows remote attackers to execute arbitrary code via membershipType parameter.

  • CVE-2024-0307HigJan 8, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login_process.php. The manipulation of the argument password leads to sql injection. The attack can be initiated…

  • CVE-2024-0306HigJan 8, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been classified as critical. This affects an unknown part of the file /admin/admin_login_process.php. The manipulation of the argument admin_password leads to sql injection. It is possible to…

  • CVE-2024-0268HigJan 7, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Kashipara Hospital Management System up to 1.0. Affected by this issue is some unknown functionality of the file registration.php. The manipulation of the argument name/email/pass/gender/age/city leads to sql…

  • CVE-2024-0267HigJan 7, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in Kashipara Hospital Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file login.php of the component Parameter Handler. The manipulation of the argument email/password leads to sql…

  • CVE-2025-5214HigMay 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Kashipara Responsive Online Learing Platform 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /courses/course_detail_user_new.php. The manipulation of the argument ID leads to sql injection. The…

  • CVE-2024-54928HigDec 9, 2024
    risk 0.47cvss 7.2epss 0.00

    kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,

  • CVE-2024-54927HigDec 9, 2024
    risk 0.47cvss 7.2epss 0.00

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php.

  • CVE-2024-54933HigDec 9, 2024
    risk 0.47cvss 7.2epss 0.00

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.

  • CVE-2024-54930HigDec 9, 2024
    risk 0.47cvss 7.2epss 0.00

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.

  • CVE-2024-54922HigDec 9, 2024
    risk 0.47cvss 7.2epss 0.01

    A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, lastname, and username parameters.

  • CVE-2024-54929HigDec 9, 2024
    risk 0.47cvss 7.2epss 0.00

    KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php.

  • CVE-2024-50831HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection was found in /admin/admin_user.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.

  • CVE-2024-50830HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/calendar_of_events.php in kashipara E-learning Management System Project 1.0 via the date_start, date_end, and title parameters.

  • CVE-2024-50829HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0 via the unit parameter.

  • CVE-2024-50828HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/edit_department.php in kashipara E-learning Management System Project 1.0 via the d parameter.

  • CVE-2024-50827HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 via the subject_code parameter.

  • CVE-2024-50826HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 via the title and content parameters.

  • CVE-2024-50825HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 via the school_year parameter.

  • CVE-2024-50824HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.

  • CVE-2024-50835HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.01

    A SQL Injection vulnerability was found in /admin/edit_student.php in KASHIPARA E-learning Management System Project 1.0 via the cys, un, ln, fn, and id parameters.

  • CVE-2024-50834HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.01

    A SQL Injection was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0 via the firstname and lastname parameters.

  • CVE-2024-50832HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.01

    A SQL Injection vulnerability was found in /admin/edit_class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.

  • CVE-2024-41236HigAug 28, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter of the Admin Login Page

  • CVE-2024-42767HigAug 22, 2024
    risk 0.47cvss 7.2epss 0.01

    Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.

  • CVE-2024-42776HigAug 22, 2024
    risk 0.47cvss 7.2epss 0.01

    Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.

  • CVE-2022-30818HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.01

    Wedding Management System v1.0 is vulnerable to SQL injection via /Wedding-Management/admin/blog_events_edit.php?id=31.

  • CVE-2024-42768MedAug 22, 2024
    risk 0.44cvss 6.8epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php.

  • CVE-2024-44653MedNov 17, 2025
    risk 0.42cvss 6.5epss 0.00

    Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php.

  • CVE-2024-44651MedNov 17, 2025
    risk 0.42cvss 6.5epss 0.00

    Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover.php.

  • CVE-2024-44652MedNov 17, 2025
    risk 0.42cvss 6.5epss 0.00

    Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastname, and user_address parameters in user_register.php.

  • CVE-2024-41252MedAug 7, 2024
    risk 0.42cvss 6.5epss 0.00

    An Incorrect Access Control vulnerability was found in /smsa/admin_student_register_approval.php and /smsa/admin_student_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve…