VYPR

Vendor CVEs

Lopalopa

All CVEs

101 total · sorted by risk
  • CVE-2024-54934CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.

  • CVE-2024-54932CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.

  • CVE-2024-54931CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.

  • CVE-2024-54925CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.

  • CVE-2024-54923CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the department parameter.

  • CVE-2024-54921CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username, firstname, lastname, and class_id parameters.

  • CVE-2024-54918CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.

  • CVE-2024-54920CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the firstname, lastname, and class_id parameters.

  • CVE-2024-50823CriNov 14, 2024
    risk 0.64cvss 9.8epss 0.00

    A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.

  • CVE-2024-50833CriNov 14, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password parameters.

  • CVE-2024-42797CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music playlist entries.

  • CVE-2024-42784CriAug 21, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in "/music/controller.php?page=view_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.

  • CVE-2024-42783CriAug 21, 2024
    risk 0.64cvss 9.8epss 0.00

    Kashipara Music Management System v1.0 is vulnerable to SQL Injection via /music/manage_playlist_items.php. An attacker can execute arbitrary SQL commands via the "pid" parameter.

  • CVE-2024-42782CriAug 21, 2024
    risk 0.64cvss 9.8epss 0.00

    A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "search" parameter.

  • CVE-2024-42781CriAug 21, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email parameter.

  • CVE-2024-42777CriAug 21, 2024
    risk 0.64cvss 9.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=signup" of Kashipara Music Management System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-40486CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email or password Login parameters.

  • CVE-2024-40482CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-41237CriAug 7, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.

  • CVE-2025-45322HigMay 5, 2025
    risk 0.57cvss 8.8epss 0.00

    kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the checkid parameter.

  • CVE-2025-45321HigMay 5, 2025
    risk 0.57cvss 8.8epss 0.00

    kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.php via the parameter: rPassword.

  • CVE-2024-54926HigDec 9, 2024
    risk 0.57cvss 8.8epss 0.01

    A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the school_year parameter.

  • CVE-2024-42791HigAug 26, 2024
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_genre.

  • CVE-2024-42786HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability in "/music/view_user.php" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter of View User Profile Page.

  • CVE-2024-42785HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability in /music/index.php?page=view_playlist in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.

  • CVE-2024-42780HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-42779HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-42778HigAug 21, 2024
    risk 0.57cvss 8.8epss 0.01

    An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-40488HigAug 12, 2024
    risk 0.57cvss 8.8epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the administrator into deleting valid member data via a crafted HTML page, as demonstrated by a Delete Member action at the…

  • CVE-2024-22917HigFeb 27, 2024
    risk 0.56cvss 8.6epss 0.01

    SQL injection vulnerability in Dynamic Lab Management System Project in PHP v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.

  • CVE-2024-42793HigAug 28, 2024
    risk 0.52cvss 8.0epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted request to the /music/ajax.php?action=save_user page.

  • CVE-2024-54938HigDec 9, 2024
    risk 0.49cvss 7.5epss 0.01

    A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads.

  • CVE-2024-42798HigSep 16, 2024
    risk 0.49cvss 7.6epss 0.00

    An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Management System v1.0. This allows a low privileged attacker to take over the administrator account.

  • CVE-2024-40487HigAug 12, 2024
    risk 0.49cvss 7.6epss 0.01

    A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0, which allows remote attackers to execute arbitrary code via membershipType parameter.

  • CVE-2024-0307HigJan 8, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login_process.php. The manipulation of the argument password leads to sql injection. The attack can be initiated…

  • CVE-2024-0306HigJan 8, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been classified as critical. This affects an unknown part of the file /admin/admin_login_process.php. The manipulation of the argument admin_password leads to sql injection. It is possible to…

  • CVE-2025-5214HigMay 27, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Kashipara Responsive Online Learing Platform 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /courses/course_detail_user_new.php. The manipulation of the argument ID leads to sql injection. The…

  • CVE-2024-54928HigDec 9, 2024
    risk 0.47cvss 7.2epss 0.00

    kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,

  • CVE-2024-54927HigDec 9, 2024
    risk 0.47cvss 7.2epss 0.00

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php.

  • CVE-2024-54933HigDec 9, 2024
    risk 0.47cvss 7.2epss 0.00

    Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.

  • CVE-2024-54922HigDec 9, 2024
    risk 0.47cvss 7.2epss 0.01

    A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, lastname, and username parameters.

  • CVE-2024-54929HigDec 9, 2024
    risk 0.47cvss 7.2epss 0.00

    KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php.

  • CVE-2024-50831HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection was found in /admin/admin_user.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.

  • CVE-2024-50830HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/calendar_of_events.php in kashipara E-learning Management System Project 1.0 via the date_start, date_end, and title parameters.

  • CVE-2024-50829HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0 via the unit parameter.

  • CVE-2024-50828HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/edit_department.php in kashipara E-learning Management System Project 1.0 via the d parameter.

  • CVE-2024-50827HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 via the subject_code parameter.

  • CVE-2024-50826HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 via the title and content parameters.

  • CVE-2024-50825HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 via the school_year parameter.

  • CVE-2024-50824HigNov 14, 2024
    risk 0.47cvss 7.2epss 0.00

    A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.

Page 1 of 3