Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown
CVE-2024-3542
Disclosure Date: April 10, 2024 (last updated February 20, 2025)
A vulnerability classified as problematic was found in Campcodes Church Management System 1.0. This vulnerability affects unknown code of the file /admin/add_visitor.php. The manipulation of the argument mobile leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259912.
0
Attacker Value
Unknown
CVE-2024-3541
Disclosure Date: April 10, 2024 (last updated February 20, 2025)
A vulnerability classified as problematic has been found in Campcodes Church Management System 1.0. This affects an unknown part of the file /admin/admin_user.php. The manipulation of the argument firstname leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259911.
0
Attacker Value
Unknown
CVE-2022-45328
Disclosure Date: November 30, 2022 (last updated February 24, 2025)
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_members.php.
0
Attacker Value
Unknown
CVE-2022-41406
Disclosure Date: October 12, 2022 (last updated February 24, 2025)
An arbitrary file upload vulnerability in the /admin/admin_pic.php component of Church Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
0
Attacker Value
Unknown
CVE-2022-38595
Disclosure Date: September 15, 2022 (last updated February 24, 2025)
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_user.php.
0
Attacker Value
Unknown
CVE-2022-38594
Disclosure Date: September 15, 2022 (last updated February 24, 2025)
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_visitor.php.
0
Attacker Value
Unknown
CVE-2022-38605
Disclosure Date: September 12, 2022 (last updated February 24, 2025)
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_event.php.
0
Attacker Value
Unknown
CVE-2022-2680
Disclosure Date: August 05, 2022 (last updated February 24, 2025)
A vulnerability classified as critical has been found in SourceCodester Church Management System 1.0. Affected is an unknown function of the file /login.php. The manipulation of the argument username with the input ' OR (SELECT 7064 FROM(SELECT COUNT(*),CONCAT(0x71627a7671,(SELECT (ELT(7064=7064,1))),0x716b707871,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- jURL leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-205668.
0
Attacker Value
Unknown
CVE-2021-41661
Disclosure Date: June 13, 2022 (last updated February 23, 2025)
Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on the web server by uploading a PHP webshell.
0
Attacker Value
Unknown
CVE-2022-1084
Disclosure Date: March 29, 2022 (last updated February 23, 2025)
A vulnerability classified as critical was found in SourceCodester One Church Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /one_church/userregister.php. The manipulation leads to authentication bypass. The attack can be launched remotely.
0