Vendor CVEs
Sourcecodester
All CVEs
2,498 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-40887 | Cri | 0.64 | 9.8 | 0.01 | Sep 29, 2022 | SourceCodester Best Student Result Management System 1.0 is vulnerable to SQL Injection. | ||
| CVE-2022-30004 | Cri | 0.64 | 9.8 | 0.02 | Sep 26, 2022 | Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection.. | ||
| CVE-2022-40030 | Cri | 0.64 | 9.8 | 0.01 | Sep 21, 2022 | SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php. | ||
| CVE-2022-37138 | Cri | 0.64 | 9.8 | 0.01 | Sep 14, 2022 | Loan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as Administrator after injecting username form. | ||
| CVE-2022-36202 | Cri | 0.64 | 9.8 | 0.01 | Aug 31, 2022 | Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter. | ||
| CVE-2022-37152 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob" parameter in "/classes/Users.php?f=save_client" | ||
| CVE-2022-28533 | Cri | 0.64 | 9.8 | 0.02 | May 5, 2022 | Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php. | ||
| CVE-2022-28530 | Cri | 0.64 | 9.8 | 0.02 | May 5, 2022 | Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory. | ||
| CVE-2022-28568 | Cri | 0.64 | 9.8 | 0.03 | May 4, 2022 | Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored. | ||
| CVE-2022-28512 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2022 | A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters. | ||
| CVE-2021-43506 | Cri | 0.64 | 9.8 | 0.02 | Mar 31, 2022 | An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter in Login.php. | ||
| CVE-2021-45865 | Cri | 0.64 | 9.8 | 0.01 | Mar 29, 2022 | A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functionality. | ||
| CVE-2021-44088 | Cri | 0.64 | 9.8 | 0.03 | Mar 17, 2022 | An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters. | ||
| CVE-2021-44087 | Cri | 0.64 | 9.8 | 0.04 | Mar 17, 2022 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload. | ||
| CVE-2021-43510 | Cri | 0.64 | 9.8 | 0.08 | Feb 1, 2022 | SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php. | ||
| CVE-2021-43509 | Cri | 0.64 | 9.8 | 0.02 | Feb 1, 2022 | SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php. | ||
| CVE-2020-36064 | Cri | 0.64 | 9.8 | 0.01 | Jan 31, 2022 | Online Course Registration v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised. | ||
| CVE-2020-25905 | Cri | 0.64 | 9.8 | 0.02 | Jan 28, 2022 | An SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1) login.php or (2) LoginAsAdmin.php. | ||
| CVE-2021-45435 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2022 | An SQL Injection vulnerability exists in Sourcecodester Simple Cold Storage Management System using PHP/OOP 1.0 via the username field in login.php. | ||
| CVE-2021-46428 | Cri | 0.64 | 9.8 | 0.03 | Jan 27, 2022 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parameter in SystemSettings.php. | ||
| CVE-2021-46427 | Cri | 0.64 | 9.8 | 0.02 | Jan 27, 2022 | An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php. | ||
| CVE-2021-46451 | Cri | 0.64 | 9.8 | 0.01 | Jan 24, 2022 | An SQL Injection vulnerabilty exists in Sourcecodester Online Project Time Management System 1.0 via the pid parameter in the load_file function. | ||
| CVE-2021-43420 | Cri | 0.64 | 9.8 | 0.01 | Jan 24, 2022 | SQL injection vulnerability in Login.php in Sourcecodester Online Payment Hub v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter. | ||
| CVE-2021-41928 | Cri | 0.64 | 9.8 | 0.02 | Jan 24, 2022 | SQL injection in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) 1.0 by oretnom23, allows attackers to execute arbitrary code via the rid parameter to the view_recipe page. | ||
| CVE-2021-41660 | Cri | 0.64 | 9.8 | 0.01 | Jan 24, 2022 | SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php. | ||
| CVE-2021-41659 | Cri | 0.64 | 9.8 | 0.01 | Jan 24, 2022 | SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username or password field. | ||
| CVE-2021-41472 | Cri | 0.64 | 9.8 | 0.01 | Jan 24, 2022 | SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password parameters. | ||
| CVE-2021-41471 | Cri | 0.64 | 9.8 | 0.01 | Jan 24, 2022 | SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the email and Password parameters. | ||
| CVE-2021-40908 | Cri | 0.64 | 9.8 | 0.03 | Jan 24, 2022 | SQL injection vulnerability in Login.php in Sourcecodester Purchase Order Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter. | ||
| CVE-2021-40907 | Cri | 0.64 | 9.8 | 0.01 | Jan 24, 2022 | SQL injection vulnerability in Sourcecodester Storage Unit Rental Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /storage/classes/Login.php. | ||
| CVE-2021-40596 | Cri | 0.64 | 9.8 | 0.01 | Jan 24, 2022 | SQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to execute arbitrary SQL commands via the faculty_id parameter. | ||
| CVE-2021-40595 | Cri | 0.64 | 9.8 | 0.01 | Jan 21, 2022 | SQL injection vulnerability in Sourcecodester Online Leave Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /leave_system/classes/Login.php. | ||
| CVE-2021-40247 | Cri | 0.64 | 9.8 | 0.03 | Jan 21, 2022 | SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field. | ||
| CVE-2021-46309 | Cri | 0.64 | 9.8 | 0.02 | Jan 21, 2022 | An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter. | ||
| CVE-2021-46308 | Cri | 0.64 | 9.8 | 0.02 | Jan 21, 2022 | An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter. | ||
| CVE-2021-46201 | Cri | 0.64 | 9.8 | 0.02 | Jan 21, 2022 | An SQL Injection vulnerability exists in Sourcecodester Online Resort Management System 1.0 via the id parameterv in /orms/ node. | ||
| CVE-2021-46200 | Cri | 0.64 | 9.8 | 0.02 | Jan 21, 2022 | An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php. | ||
| CVE-2021-46061 | Cri | 0.64 | 9.8 | 0.02 | Jan 20, 2022 | An SQL Injection vulnerability exists in Sourcecodester Computer and Mobile Repair Shop Management system (RSMS) 1.0 via the code parameter in /rsms/ node app. | ||
| CVE-2021-44245 | Cri | 0.64 | 9.8 | 0.01 | Jan 20, 2022 | An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) username and (2) contactno parameters. | ||
| CVE-2021-44244 | Cri | 0.64 | 9.8 | 0.01 | Jan 20, 2022 | An SQL Injection vulnerabiity exists in Sourcecodester Logistic Hub Parcel's Management System 1.0 via the username parameter in login.php. | ||
| CVE-2021-44090 | Cri | 0.64 | 9.8 | 0.01 | Jan 20, 2022 | An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter. | ||
| CVE-2021-46013 | Cri | 0.64 | 9.8 | 0.03 | Jan 18, 2022 | An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability to enable remote code execution on the affected web server. Once a php webshell containing "<?php system($_GET["cmd"]); ?>" gets… | ||
| CVE-2021-45411 | Cri | 0.64 | 9.8 | 0.04 | Jan 12, 2022 | In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution. | ||
| CVE-2021-45334 | Cri | 0.64 | 9.8 | 0.03 | Jan 10, 2022 | Sourcecodester Online Thesis Archiving System 1.0 is vulnerable to SQL Injection. An attacker can bypass admin authentication and gain access to admin panel using SQL Injection | ||
| CVE-2021-44280 | Cri | 0.64 | 9.8 | 0.02 | Dec 1, 2021 | attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the makeSafe function. | ||
| CVE-2021-42670 | Cri | 0.64 | 9.8 | 0.08 | Nov 5, 2021 | A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announcements_student.php web page. As a result a malicious user can extract sensitive data from the web server and in some cases use this vulnerability in order to… | ||
| CVE-2021-42668 | Cri | 0.64 | 9.8 | 0.05 | Nov 5, 2021 | A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter in the my_classmates.php web page.. As a result, an attacker can extract sensitive data from the web server and in some cases can use this vulnerability in order to get a… | ||
| CVE-2021-42665 | Cri | 0.64 | 9.8 | 0.05 | Nov 5, 2021 | An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an attacker to bypass authentication. | ||
| CVE-2021-41492 | Cri | 0.64 | 9.8 | 0.02 | Nov 3, 2021 | Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in actions.php. | ||
| CVE-2021-43130 | Cri | 0.64 | 9.8 | 0.02 | Nov 3, 2021 | An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the username parameter in customer/login.php. |
- risk 0.64cvss 9.8epss 0.01
SourceCodester Best Student Result Management System 1.0 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.02
Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection..
- risk 0.64cvss 9.8epss 0.01
SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php.
- risk 0.64cvss 9.8epss 0.01
Loan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as Administrator after injecting username form.
- risk 0.64cvss 9.8epss 0.01
Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob" parameter in "/classes/Users.php?f=save_client"
- risk 0.64cvss 9.8epss 0.02
Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php.
- risk 0.64cvss 9.8epss 0.02
Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory.
- risk 0.64cvss 9.8epss 0.03
Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter in Login.php.
- risk 0.64cvss 9.8epss 0.01
A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functionality.
- risk 0.64cvss 9.8epss 0.03
An SQL Injection vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows a remote attacker to bypass authentication via unsanitized login parameters.
- risk 0.64cvss 9.8epss 0.04
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Attendance and Payroll System v1.0 which allows an unauthenticated remote attacker to upload a maliciously crafted PHP via photo upload.
- risk 0.64cvss 9.8epss 0.08
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the username field in login.php.
- risk 0.64cvss 9.8epss 0.02
SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the id parameter in view-service.php.
- risk 0.64cvss 9.8epss 0.01
Online Course Registration v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerabilty exists in Sourcecodester Mobile Shop System in PHP MySQL 1.0 via the email parameter in (1) login.php or (2) LoginAsAdmin.php.
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerability exists in Sourcecodester Simple Cold Storage Management System using PHP/OOP 1.0 via the username field in login.php.
- risk 0.64cvss 9.8epss 0.03
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versions via the bot_avatar parameter in SystemSettings.php.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php.
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerabilty exists in Sourcecodester Online Project Time Management System 1.0 via the pid parameter in the load_file function.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Login.php in Sourcecodester Online Payment Hub v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.
- risk 0.64cvss 9.8epss 0.02
SQL injection in Sourcecodester Try My Recipe (Recipe Sharing Website - CMS) 1.0 by oretnom23, allows attackers to execute arbitrary code via the rid parameter to the view_recipe page.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username or password field.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password parameters.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Sourcecodester South Gate Inn Online Reservation System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the email and Password parameters.
- risk 0.64cvss 9.8epss 0.03
SQL injection vulnerability in Login.php in Sourcecodester Purchase Order Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Sourcecodester Storage Unit Rental Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /storage/classes/Login.php.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to execute arbitrary SQL commands via the faculty_id parameter.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Sourcecodester Online Leave Management System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username parameter to /leave_system/classes/Login.php.
- risk 0.64cvss 9.8epss 0.03
SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Online Railway Reservation Sysytem 1.0 via the sid parameter.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Online Resort Management System 1.0 via the id parameterv in /orms/ node.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Computer and Mobile Repair Shop Management system (RSMS) 1.0 via the code parameter in /rsms/ node app.
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerability exists in Courcecodester COVID 19 Testing Management System (CTMS) 1.0 via the (1) username and (2) contactno parameters.
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerabiity exists in Sourcecodester Logistic Hub Parcel's Management System 1.0 via the username parameter in login.php.
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter.
- risk 0.64cvss 9.8epss 0.03
An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability to enable remote code execution on the affected web server. Once a php webshell containing "<?php system($_GET["cmd"]); ?>" gets…
- risk 0.64cvss 9.8epss 0.04
In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can log in and leverage an arbitrary file upload vulnerability to obtain remote code execution.
- risk 0.64cvss 9.8epss 0.03
Sourcecodester Online Thesis Archiving System 1.0 is vulnerable to SQL Injection. An attacker can bypass admin authentication and gain access to admin panel using SQL Injection
- risk 0.64cvss 9.8epss 0.02
attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the makeSafe function.
- risk 0.64cvss 9.8epss 0.08
A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announcements_student.php web page. As a result a malicious user can extract sensitive data from the web server and in some cases use this vulnerability in order to…
- risk 0.64cvss 9.8epss 0.05
A SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter in the my_classmates.php web page.. As a result, an attacker can extract sensitive data from the web server and in some cases can use this vulnerability in order to get a…
- risk 0.64cvss 9.8epss 0.05
An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an attacker to bypass authentication.
- risk 0.64cvss 9.8epss 0.02
Multiple SQL Injection vulnerabilities exist in Sourcecodester Simple Cashiering System (POS) 1.0 via the (1) Product Code in the pos page in cashiering. (2) id parameter in manage_products and the (3) t paramater in actions.php.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Customer Relationship Management System (CRM) 1.0 via the username parameter in customer/login.php.
Page 3 of 50