Vendor CVEs
Sourcecodester
All CVEs
2,498 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-34833 | Cri | 0.64 | 9.8 | 0.02 | Jun 17, 2024 | Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability… | ||
| CVE-2024-36673 | Cri | 0.64 | 9.8 | 0.01 | Jun 7, 2024 | Sourcecodester Pharmacy/Medical Store Point of Sale System 1.0 is vulnerable SQL Injection via login.php. This vulnerability stems from inadequate validation of user inputs for the email and password parameters, allowing attackers to inject malicious SQL queries. | ||
| CVE-2024-36779 | Cri | 0.64 | 9.8 | 0.01 | Jun 6, 2024 | Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php. | ||
| CVE-2024-36568 | Cri | 0.64 | 9.8 | 0.01 | Jun 3, 2024 | Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=. | ||
| CVE-2024-35469 | Cri | 0.64 | 9.8 | 0.01 | May 30, 2024 | A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter. | ||
| CVE-2024-34919 | Cri | 0.64 | 9.8 | 0.01 | May 17, 2024 | An arbitrary file upload vulnerability in the component \modstudent\controller.php of Pisay Online E-Learning System using PHP/MySQL v1.0 allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2024-28557 | Cri | 0.64 | 9.8 | 0.01 | Apr 15, 2024 | SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to update-admin.php. | ||
| CVE-2024-28556 | Cri | 0.64 | 9.8 | 0.01 | Apr 15, 2024 | SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin-manage-user.php. | ||
| CVE-2024-31678 | Cri | 0.64 | 9.8 | 0.01 | Apr 11, 2024 | Sourcecodester Loan Management System v1.0 is vulnerable to SQL Injection via the "password" parameter in the "login.php" file. | ||
| CVE-2024-30849 | Cri | 0.64 | 9.8 | 0.01 | Apr 5, 2024 | Arbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows remote attackers to execute arbitrary code via filename parameter in admin/products_photo.php. | ||
| CVE-2024-29303 | Cri | 0.64 | 9.8 | 0.01 | Mar 26, 2024 | The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection | ||
| CVE-2024-25239 | Cri | 0.64 | 9.8 | 0.01 | Mar 21, 2024 | SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted POST request to /emloyee_akpoly/Account/login.php. | ||
| CVE-2023-49547 | Cri | 0.64 | 9.8 | 0.01 | Mar 5, 2024 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login. | ||
| CVE-2024-24142 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2024 | Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter. | ||
| CVE-2024-25302 | Cri | 0.64 | 9.8 | 0.01 | Feb 9, 2024 | Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter. | ||
| CVE-2024-24141 | Cri | 0.64 | 9.8 | 0.01 | Jan 29, 2024 | Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter. | ||
| CVE-2023-46435 | Cri | 0.64 | 9.8 | 0.01 | Oct 26, 2023 | Sourcecodester Packers and Movers Management System v1.0 is vulnerable to SQL Injection via mpms/?p=services/view_service&id. | ||
| CVE-2023-46007 | Cri | 0.64 | 9.8 | 0.01 | Oct 18, 2023 | Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_staff.php. | ||
| CVE-2023-46006 | Cri | 0.64 | 9.8 | 0.01 | Oct 18, 2023 | Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_user.php. | ||
| CVE-2023-46005 | Cri | 0.64 | 9.8 | 0.01 | Oct 18, 2023 | Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_branch.php. | ||
| CVE-2023-30415 | Cri | 0.64 | 9.8 | 0.01 | Sep 28, 2023 | Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /inquiries/view_inquiry.php. | ||
| CVE-2023-40945 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php. | ||
| CVE-2020-36034 | Cri | 0.64 | 9.8 | 0.02 | Aug 11, 2023 | SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php. | ||
| CVE-2023-37682 | Cri | 0.64 | 9.8 | 0.01 | Aug 8, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-jms/deductScores.php. | ||
| CVE-2023-31704 | Cri | 0.64 | 9.8 | 0.01 | Jul 13, 2023 | Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privileges to the administrator's role. | ||
| CVE-2023-37628 | Cri | 0.64 | 9.8 | 0.01 | Jul 12, 2023 | Online Piggery Management System 1.0 is vulnerable to SQL Injection. | ||
| CVE-2023-31752 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/classes/Login.php. | ||
| CVE-2023-29985 | Cri | 0.64 | 9.8 | 0.01 | May 18, 2023 | Sourcecodester Student Study Center Desk Management System v1.0 admin\reports\index.php#date_from has a SQL Injection vulnerability. | ||
| CVE-2023-31857 | Cri | 0.64 | 9.8 | 0.02 | May 16, 2023 | Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution. The vulnerability path is /classes/Users.php?f=save. | ||
| CVE-2023-30092 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2023 | SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter. | ||
| CVE-2022-39989 | Cri | 0.64 | 9.8 | 0.01 | Apr 26, 2023 | An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to change the credentials. | ||
| CVE-2023-30076 | Cri | 0.64 | 9.8 | 0.01 | Apr 20, 2023 | Sourcecodester Judging Management System v1.0 is vulnerable to SQL Injection via /php-jms/print_judges.php?print_judges.php=&se_name=&sub_event_id=. | ||
| CVE-2023-27667 | Cri | 0.64 | 9.8 | 0.01 | Apr 13, 2023 | Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability. | ||
| CVE-2023-26905 | Cri | 0.64 | 9.8 | 0.01 | Mar 19, 2023 | An issue was discovered in Alphaware - Simple E-Commerce System v1.0. There is a SQL injection that can directly issue instructions to the background database system via /alphaware/details.php?id. | ||
| CVE-2023-27204 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php. | ||
| CVE-2023-27203 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php. | ||
| CVE-2023-24202 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php. | ||
| CVE-2023-24201 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php. | ||
| CVE-2023-24200 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php. | ||
| CVE-2023-24199 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php. | ||
| CVE-2023-24198 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters. | ||
| CVE-2022-47864 | Cri | 0.64 | 9.8 | 0.01 | Jan 11, 2023 | Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php. | ||
| CVE-2022-47862 | Cri | 0.64 | 9.8 | 0.01 | Jan 11, 2023 | Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php. | ||
| CVE-2022-47861 | Cri | 0.64 | 9.8 | 0.01 | Jan 11, 2023 | Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php. | ||
| CVE-2022-47866 | Cri | 0.64 | 9.8 | 0.01 | Jan 11, 2023 | Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php. | ||
| CVE-2022-47865 | Cri | 0.64 | 9.8 | 0.01 | Jan 11, 2023 | Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php. | ||
| CVE-2022-47790 | Cri | 0.64 | 9.8 | 0.01 | Jan 9, 2023 | Sourcecodester Dynamic Transaction Queuing System v1.0 is vulnerable to SQL Injection via /queuing/index.php?page=display&id=. | ||
| CVE-2021-31650 | Cri | 0.64 | 9.8 | 0.01 | Dec 16, 2022 | A SQL injection vulnerability in Sourcecodester Online Grading System 1.0 allows remote attackers to execute arbitrary SQL commands via the uname parameter. | ||
| CVE-2022-43265 | Cri | 0.64 | 9.8 | 0.01 | Nov 15, 2022 | An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-40872 | Cri | 0.64 | 9.8 | 0.01 | Oct 7, 2022 | An SQL injection vulnerability issue was discovered in Sourcecodester Simple E-Learning System 1.0., in /vcs/classRoom.php?classCode=, classCode. |
- risk 0.64cvss 9.8epss 0.02
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability…
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Pharmacy/Medical Store Point of Sale System 1.0 is vulnerable SQL Injection via login.php. This vulnerability stems from inadequate validation of user inputs for the email and password parameters, allowing attackers to inject malicious SQL queries.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component \modstudent\controller.php of Pisay Online E-Learning System using PHP/MySQL v1.0 allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to update-admin.php.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin-manage-user.php.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Loan Management System v1.0 is vulnerable to SQL Injection via the "password" parameter in the "login.php" file.
- risk 0.64cvss 9.8epss 0.01
Arbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows remote attackers to execute arbitrary code via filename parameter in admin/products_photo.php.
- risk 0.64cvss 9.8epss 0.01
The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted POST request to /emloyee_akpoly/Account/login.php.
- risk 0.64cvss 9.8epss 0.01
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Packers and Movers Management System v1.0 is vulnerable to SQL Injection via mpms/?p=services/view_service&id.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_staff.php.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_user.php.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_branch.php.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /inquiries/view_inquiry.php.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php.
- risk 0.64cvss 9.8epss 0.02
SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php-jms/deductScores.php.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privileges to the administrator's role.
- risk 0.64cvss 9.8epss 0.01
Online Piggery Management System 1.0 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/classes/Login.php.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Student Study Center Desk Management System v1.0 admin\reports\index.php#date_from has a SQL Injection vulnerability.
- risk 0.64cvss 9.8epss 0.02
Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution. The vulnerability path is /classes/Users.php?f=save.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to change the credentials.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Judging Management System v1.0 is vulnerable to SQL Injection via /php-jms/print_judges.php?print_judges.php=&se_name=&sub_event_id=.
- risk 0.64cvss 9.8epss 0.01
Auto Dealer Management System v1.0 was discovered to contain a SQL injection vulnerability.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Alphaware - Simple E-Commerce System v1.0. There is a SQL injection that can directly issue instructions to the background database system via /alphaware/details.php?id.
- risk 0.64cvss 9.8epss 0.01
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.
- risk 0.64cvss 9.8epss 0.01
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters.
- risk 0.64cvss 9.8epss 0.01
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php.
- risk 0.64cvss 9.8epss 0.01
Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php.
- risk 0.64cvss 9.8epss 0.01
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php.
- risk 0.64cvss 9.8epss 0.01
Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php.
- risk 0.64cvss 9.8epss 0.01
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Dynamic Transaction Queuing System v1.0 is vulnerable to SQL Injection via /queuing/index.php?page=display&id=.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in Sourcecodester Online Grading System 1.0 allows remote attackers to execute arbitrary SQL commands via the uname parameter.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
An SQL injection vulnerability issue was discovered in Sourcecodester Simple E-Learning System 1.0., in /vcs/classRoom.php?classCode=, classCode.
Page 2 of 50