Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2021-40261
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester CASAP Automated Enrollment System 1.0 via the (1) user_username and (2) category parameters in save_class.php, the (3) firstname, (4) class, and (5) status parameters in student_table.php, the (6) category and (7) class_name parameters in add_class1.php, the (8) fname, (9) mname,(10) lname, (11) address, (12) class, (13) gfname, (14) gmname, (15) glname, (16) rship, (17) status, (18) transport, and (19) route parameters in add_student.php, the (20) fname, (21) mname, (22) lname, (23) address, (24) class, (25) fgname, (26) gmname, (27) glname, (28) rship, (29) status, (30) transport, and (31) route parameters in save_stud.php,the (32) status, (33) fname, and (34) lname parameters in add_user.php, the (35) username, (36) firstname, and (37) status parameters in users.php, the (38) fname, (39) lname, and (40) status parameters in save_user.php, and the (41) activity_log, (42) aprjun, (43) class, (44) janmar, (45)…
0
Attacker Value
Unknown
CVE-2021-27332
Disclosure Date: July 22, 2021 (last updated February 23, 2025)
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the class_name parameter to update_class.php.
0
Attacker Value
Unknown
CVE-2021-26223
Disclosure Date: July 22, 2021 (last updated February 23, 2025)
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to view_pay.php.
0
Attacker Value
Unknown
CVE-2021-26226
Disclosure Date: July 22, 2021 (last updated February 23, 2025)
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_user.php.
0
Attacker Value
Unknown
CVE-2021-26230
Disclosure Date: July 22, 2021 (last updated February 23, 2025)
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the user information to save_user.php.
0
Attacker Value
Unknown
CVE-2021-26228
Disclosure Date: July 22, 2021 (last updated February 23, 2025)
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_class1.php.
0
Attacker Value
Unknown
CVE-2021-26229
Disclosure Date: July 22, 2021 (last updated February 23, 2025)
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_stud.php.
0
Attacker Value
Unknown
CVE-2021-26227
Disclosure Date: July 22, 2021 (last updated February 23, 2025)
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the student information parameters to edit_stud.php.
0
Attacker Value
Unknown
CVE-2021-27129
Disclosure Date: April 15, 2021 (last updated February 22, 2025)
CASAP Automated Enrollment System version 1.0 contains a cross-site scripting (XSS) vulnerability through the Students > Edit > ROUTE parameter.
0
Attacker Value
Unknown
CVE-2021-26201
Disclosure Date: February 15, 2021 (last updated February 22, 2025)
The Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authentication bypass. An attacker can obtain access to the admin panel by injecting a SQL query in the username field of the login page.
0