Show filters
49 Total Results
Displaying 1-10 of 49
Sort by:
Attacker Value
Very High
CVE-2021-42580
Disclosure Date: November 15, 2021 (last updated February 23, 2025)
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated remote command execution.
2
Attacker Value
Unknown
CVE-2025-1590
Disclosure Date: February 23, 2025 (last updated February 24, 2025)
A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/modules/lesson/index.php of the component List of Lessons Page. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely.
0
Attacker Value
Unknown
CVE-2025-1589
Disclosure Date: February 23, 2025 (last updated February 24, 2025)
A vulnerability was found in SourceCodester E-Learning System 1.0 and classified as problematic. This issue affects some unknown processing of the file /register.php of the component User Registration Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely.
0
Attacker Value
Unknown
CVE-2024-12127
Disclosure Date: December 17, 2024 (last updated December 18, 2024)
The Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 0.0.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-54935
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.
0
Attacker Value
Unknown
CVE-2024-54933
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.
0
Attacker Value
Unknown
CVE-2024-54930
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.
0
Attacker Value
Unknown
CVE-2024-54922
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, lastname, and username parameters.
0
Attacker Value
Unknown
CVE-2024-54926
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the school_year parameter.
0
Attacker Value
Unknown
CVE-2024-54920
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the firstname, lastname, and class_id parameters.
0