School Dormitory Management System
Products
1- 28 CVEs
Recent CVEs
28| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-18795 | Cri | 0.67 | 9.8 | 0.03 | Nov 16, 2018 | School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter. | ||
| CVE-2018-18793 | Cri | 0.67 | 9.8 | 0.10 | Nov 16, 2018 | School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos. | ||
| CVE-2024-42575 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at substaff.php. | ||
| CVE-2024-42574 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at attendance.php. | ||
| CVE-2024-42573 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at dtmarks.php. | ||
| CVE-2024-42572 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php. | ||
| CVE-2024-42571 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php. | ||
| CVE-2024-42570 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at admininsert.php. | ||
| CVE-2024-42569 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php. | ||
| CVE-2024-42568 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport parameter at vehicle.php. | ||
| CVE-2024-42567 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at /search.php?action=2. | ||
| CVE-2024-42566 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2024 | School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php | ||
| CVE-2022-30512 | Cri | 0.64 | 9.8 | 0.10 | Jun 2, 2022 | School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31. | ||
| CVE-2022-30511 | Cri | 0.64 | 9.8 | 0.04 | Jun 2, 2022 | School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/view_details.php:4. | ||
| CVE-2022-30510 | Cri | 0.64 | 9.8 | 0.04 | Jun 2, 2022 | School Dormitory Management System 1.0 is vulnerable to SQL Injection via reports/daily_collection_report.php:59. | ||
| CVE-2022-30886 | Cri | 0.64 | 9.8 | 0.02 | May 20, 2022 | School Dormitory Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /dms/admin/reports/daily_collection_report.php. | ||
| CVE-2018-18794 | Hig | 0.60 | 8.8 | 0.02 | Nov 16, 2018 | School Event Management System 1.0 allows CSRF via user/controller.php?action=edit. | ||
| CVE-2023-49982 | Hig | 0.57 | 8.8 | 0.01 | Mar 21, 2024 | Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts. | ||
| CVE-2023-49983 | Med | 0.44 | 6.8 | 0.01 | Mar 21, 2024 | A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter. | ||
| CVE-2023-49985 | Med | 0.42 | 6.5 | 0.00 | Mar 21, 2024 | A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cname parameter. |
- risk 0.67cvss 9.8epss 0.03
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
- risk 0.67cvss 9.8epss 0.10
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at substaff.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at attendance.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at dtmarks.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at unitmarks.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at insertattendance.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at admininsert.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the medium parameter at paidclass.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the transport parameter at vehicle.php.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the sid parameter at /search.php?action=2.
- risk 0.64cvss 9.8epss 0.01
School Management System commit bae5aa was discovered to contain a SQL injection vulnerability via the password parameter at login.php
- risk 0.64cvss 9.8epss 0.10
School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/payment_history.php:31.
- risk 0.64cvss 9.8epss 0.04
School Dormitory Management System 1.0 is vulnerable to SQL Injection via accounts/view_details.php:4.
- risk 0.64cvss 9.8epss 0.04
School Dormitory Management System 1.0 is vulnerable to SQL Injection via reports/daily_collection_report.php:59.
- risk 0.64cvss 9.8epss 0.02
School Dormitory Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /dms/admin/reports/daily_collection_report.php.
- risk 0.60cvss 8.8epss 0.02
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
- risk 0.57cvss 8.8epss 0.01
Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts.
- risk 0.44cvss 6.8epss 0.01
A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
- risk 0.42cvss 6.5epss 0.00
A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cname parameter.