Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown
CVE-2022-2722
Disclosure Date: August 09, 2022 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Simple Student Information System and classified as critical. This issue affects some unknown processing of the file manage_course.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-205835.
0
Attacker Value
Unknown
CVE-2022-2705
Disclosure Date: August 08, 2022 (last updated February 24, 2025)
A vulnerability was found in SourceCodester Simple Student Information System. It has been rated as critical. This issue affects some unknown processing of the file admin/departments/manage_department.php. The manipulation of the argument id with the input -5756%27%20UNION%20ALL%20SELECT%20NULL,database(),user(),NULL,NULL,NULL,NULL--%20- leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-205829 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-34550
Disclosure Date: July 27, 2022 (last updated February 24, 2025)
Sims v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /addNotifyServlet. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the notifyInfo parameter.
0
Attacker Value
Unknown
CVE-2022-1819
Disclosure Date: May 24, 2022 (last updated February 23, 2025)
A vulnerability, which was classified as problematic, was found in Student Information System 1.0. Affected is admin/?page=students of the Student Roll module. The manipulation with the input <script>alert(1)</script> leads to authenticated cross site scripting. Exploit details have been disclosed to the public.
0
Attacker Value
Unknown
CVE-2022-24231
Disclosure Date: April 05, 2022 (last updated February 23, 2025)
Simple Student Information System v1.0 was discovered to contain a SQL injection vulnerability via add/Student.
0