VYPR

Vendor CVEs

Sourcecodester

All CVEs

2,501 total · sorted by risk
  • CVE-2024-0502MedJan 13, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester House Rental Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file manage_user.php of the component Edit User. The manipulation of the argument id/name/username leads to sql…

  • CVE-2023-6312MedNov 27, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Loan Management System 1.0. It has been classified as critical. Affected is the function delete_user of the file deleteUser.php of the component Users Page. The manipulation of the argument user_id leads to sql injection. It is…

  • CVE-2023-6311MedNov 27, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Loan Management System 1.0 and classified as critical. This issue affects the function delete_ltype of the file delete_ltype.php of the component Loan Type Page. The manipulation of the argument ltype_id leads to sql injection. The…

  • CVE-2023-6310MedNov 27, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability has been found in SourceCodester Loan Management System 1.0 and classified as critical. This vulnerability affects the function delete_borrower of the file deleteBorrower.php. The manipulation of the argument borrower_id leads to sql injection. The attack can be…

  • CVE-2023-5919MedNov 2, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Company Website CMS 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /dashboard/createblog of the component Create Blog Page. The manipulation leads to unrestricted upload. The attack…

  • CVE-2023-5423MedOct 5, 2023
    risk 0.31cvss 4.7epss 0.00

    A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/ajax.php?action=confirm_order. The manipulation of the argument id leads to sql injection. The attack can be…

  • CVE-2023-36317MedAug 23, 2023
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) vulnerability in sourcecodester Student Study Center Desk Management System 1.0 allows attackers to run arbitrary code via crafted GET request to web application URL.

  • CVE-2023-2962MedMay 29, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Faculty Evaluation System 1.0. Affected by this issue is some unknown functionality of the file index.php?page=edit_user. The manipulation of the argument id leads to sql injection. The attack…

  • CVE-2023-2369MedApr 28, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Faculty Evaluation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/manage_restriction.php. The manipulation of the argument id leads to sql injection. The attack may be initiated…

  • CVE-2023-2368MedApr 28, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Faculty Evaluation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file index.php?page=manage_questionnaire. The manipulation of the argument id leads to sql injection. The attack can be…

  • CVE-2023-2367MedApr 28, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Faculty Evaluation System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/manage_academic.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack…

  • CVE-2023-2154MedApr 18, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/?page=reminders/view_reminder. The manipulation of the argument id leads to sql injection. It is possible to initiate the…

  • CVE-2023-2150MedApr 18, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Task Reminder System 1.0. This issue affects some unknown processing of the file Master.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The…

  • CVE-2023-1854MedApr 5, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file admin/. The manipulation leads to session expiration. It is possible to launch the attack remotely. The exploit has…

  • CVE-2023-1740MedMar 30, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Air Cargo Management System 1.0. It has been classified as critical. Affected is an unknown function of the file admin/user/manage_user.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql…

  • CVE-2023-1559MedMar 22, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as problematic was found in SourceCodester Storage Unit Rental Management System 1.0. This vulnerability affects unknown code of the file classes/Users.php?f=save. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The…

  • CVE-2023-1433MedMar 16, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Gadget Works Online Ordering System 1.0. It has been classified as problematic. This affects an unknown part of the file admin/products/controller.php?action=add of the component Products Handler. The manipulation of the argument…

  • CVE-2023-1407MedMar 15, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. The…

  • CVE-2023-1391MedMar 14, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as problematic, was found in SourceCodester Online Tours & Travels Management System 1.0. Affected is an unknown function of the file admin/ab.php. The manipulation of the argument img leads to unrestricted upload. It is possible to launch…

  • CVE-2023-1360MedMar 12, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Employee Payslip Generator with Sending Mail 1.2.0 and classified as critical. This issue affects some unknown processing of the file classes/Users.php?f=save of the component New User Creation. The manipulation of the argument…

  • CVE-2023-1054MedFeb 27, 2023
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=user/manage. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely.…

  • CVE-2023-1053MedFeb 27, 2023
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in SourceCodester Music Gallery Site 1.0 and classified as critical. This issue affects some unknown processing of the file view_category.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The…

  • CVE-2023-0560MedJan 28, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Online Tours & Travels Management System 1.0. This issue affects some unknown processing of the file admin/practice_pdf.php. The manipulation of the argument id leads to sql injection. The attack…

  • CVE-2023-0534MedJan 27, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester Online Tours & Travels Management System 1.0. This affects an unknown part of the file admin/expense_report.php. The manipulation of the argument to_date leads to sql injection. It is possible to…

  • CVE-2023-0533MedJan 27, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Online Tours & Travels Management System 1.0. Affected by this issue is some unknown functionality of the file admin/expense_report.php. The manipulation of the argument from_date leads to sql…

  • CVE-2023-0532MedJan 27, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as critical was found in SourceCodester Online Tours & Travels Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/disapprove_user.php. The manipulation of the argument id leads to sql injection. The…

  • CVE-2023-0531MedJan 27, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Management System 1.0. Affected is an unknown function of the file admin/booking_report.php. The manipulation of the argument to_date leads to sql injection. It is possible to launch…

  • CVE-2023-0530MedJan 27, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/approve_user.php. The manipulation of the argument id leads to sql injection. The attack may be…

  • CVE-2023-0529MedJan 27, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/add_payment.php. The manipulation of the argument id leads to sql injection. The attack can be…

  • CVE-2023-0528MedJan 27, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. This affects an unknown part of the file admin/abc.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack…

  • CVE-2023-0257MedJan 12, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /fos/admin/index.php?page=menu of the component Menu Form. The manipulation of the argument Image…

  • CVE-2022-4278MedDec 3, 2022
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Human Resource Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /hrm/employeeadd.php. The manipulation of the argument empid leads to sql injection. The attack may be…

  • CVE-2022-4232MedNov 30, 2022
    risk 0.31cvss 4.7epss 0.00

    A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. Affected is an unknown function. The manipulation of the argument cmd leads to unrestricted upload. It is possible to launch the attack remotely. VDB-214590 is the…

  • CVE-2022-3868MedNov 5, 2022
    risk 0.31cvss 4.7epss 0.00

    A vulnerability classified as critical has been found in SourceCodester Sanitization Management System. Affected is an unknown function of the file /php-sms/classes/Master.php?f=save_quote. The manipulation of the argument id leads to sql injection. It is possible to launch the…

  • CVE-2022-3549MedOct 17, 2022
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /csms/admin/?page=user/manage_user of the component Avatar Handler. The manipulation leads to…

  • CVE-2022-40029MedSep 21, 2022
    risk 0.31cvss 4.8epss 0.00

    SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newProjectValidation.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the…

  • CVE-2022-40028MedSep 21, 2022
    risk 0.31cvss 4.8epss 0.00

    SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component newProjectValidation.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the…

  • CVE-2021-41731MedSep 16, 2022
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS vulnerability exists in )Sourcecodester News247 News Magazine (CMS) PHP 5.6 or higher and MySQL 5.7 or higher via the blog category name field

  • CVE-2022-2749MedAug 11, 2022
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Gym Management System. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /mygym/admin/index.php?view_exercises. The manipulation leads to unrestricted upload. The attack can be…

  • CVE-2022-2700MedAug 8, 2022
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Gym Management System. This affects an unknown part of the component GET Parameter Handler. The manipulation of the argument day leads to sql injection. It is possible to initiate the attack remotely. The…

  • CVE-2022-2018MedJun 9, 2022
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. Affected is an unknown function of the file /admin/?page=inmates/view_inmate of the component Inmate Handler. The manipulation of the argument id with the input…

  • CVE-2022-2017MedJun 9, 2022
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /pms/admin/visits/view_visit.php of the component Visit Handler. The manipulation of the argument id with the input…

  • CVE-2021-44114MedJan 31, 2022
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Stock Management System in PHP/OOP 1.0, which allows remote malicious users to execute arbitrary remote code execution via create user function.

  • CVE-2021-46078MedJan 6, 2022
    risk 0.31cvss 4.8epss 0.01

    An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload malicious files leading to a Stored Cross-Site Scripting vulnerability.

  • CVE-2021-46074MedJan 6, 2022
    risk 0.31cvss 4.8epss 0.01

    A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Settings Section in login panel.

  • CVE-2021-46073MedJan 6, 2022
    risk 0.31cvss 4.8epss 0.03

    A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the User List Section in login panel.

  • CVE-2021-41962MedDec 16, 2021
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Owner fullname parameter in a Send Service Request in vehicle_service.

  • CVE-2020-28071MedDec 23, 2020
    risk 0.31cvss 4.8epss 0.01

    SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' and reach a stored XSS.

  • CVE-2024-57523MedFeb 6, 2025
    risk 0.29cvss 4.5epss 0.00

    Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authenticated admin user.

  • CVE-2026-75151MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be initiated remotely.

Page 38 of 51