VYPR
Vendor

Simple College Project

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2020-28172CriMar 31, 2021
    risk 0.64cvss 9.8epss 0.03

    A SQL injection vulnerability in Simple College Website 1.0 allows remote unauthenticated attackers to bypass the admin authentication mechanism in college_website/admin/ajax.php?action=login, thus gaining access to the website administrative panel.

  • CVE-2020-28173HigMar 31, 2021
    risk 0.47cvss 7.2epss 0.03

    Simple College Website 1.0 allows a user to conduct remote code execution via /alumni/admin/ajax.php?action=save_settings when uploading a malicious file using the image upload functionality, which is stored in /alumni/admin/assets/uploads/.