Show filters
53 Total Results
Displaying 1-10 of 53
Sort by:
Attacker Value
Very High

CVE-2021-36624

Disclosure Date: July 30, 2021 (last updated February 23, 2025)
Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Attacker Value
Unknown

CVE-2024-48048

Disclosure Date: October 17, 2024 (last updated February 26, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in WSIFY – Sales can fly Wsify Widget allows Stored XSS.This issue affects Wsify Widget: from n/a through 1.0.
0
Attacker Value
Unknown

CVE-2023-38330

Disclosure Date: August 02, 2023 (last updated February 25, 2025)
OXID eShop Enterprise Edition 6.5.0 – 6.5.2 before 6.5.3 allows uploading files with modified headers in the administration area. An attacker can upload a file with a modified header to create a HTTP Response Splitting attack.
Attacker Value
Unknown

CVE-2023-3184

Disclosure Date: June 09, 2023 (last updated February 25, 2025)
A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save. The manipulation of the argument firstname/middlename/lastname/username leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-231164.
Attacker Value
Unknown

CVE-2023-1983

Disclosure Date: April 11, 2023 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/products/manage_product.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-225530 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-26773

Disclosure Date: April 10, 2023 (last updated February 24, 2025)
Cross Site Scripting vulnerability found in Sales Tracker Management System v.1.0 allows a remote attacker to gain privileges via the product list function in the Master.php file.
Attacker Value
Unknown

CVE-2023-26774

Disclosure Date: April 10, 2023 (last updated October 08, 2023)
An issue found in Sales Tracker Management System v.1.0 allows a remote attacker to access sensitive information via sales.php component of the admin/reports endpoint.
Attacker Value
Unknown

CVE-2023-1363

Disclosure Date: March 13, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. Affected is an unknown function of the component Add User Account. The manipulation of the argument username leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-222870 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-1351

Disclosure Date: March 11, 2023 (last updated February 24, 2025)
A vulnerability classified as critical has been found in SourceCodester Computer Parts Sales and Inventory System 1.0. This affects an unknown part of the file cust_transac.php. The manipulation of the argument phonenumber leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222849 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-1292

Disclosure Date: March 09, 2023 (last updated February 24, 2025)
A vulnerability has been found in SourceCodester Sales Tracker Management System 1.0 and classified as critical. This vulnerability affects the function delete_client of the file classes/Master.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-222646 is the identifier assigned to this vulnerability.