Show filters
60 Total Results
Displaying 21-30 of 60
Sort by:
Attacker Value
Unknown
CVE-2024-50823
Disclosure Date: November 14, 2024 (last updated November 19, 2024)
A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.
0
Attacker Value
Unknown
CVE-2024-50836
Disclosure Date: November 14, 2024 (last updated November 19, 2024)
A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the firstname and lastname parameters.
0
Attacker Value
Unknown
CVE-2024-50835
Disclosure Date: November 14, 2024 (last updated November 19, 2024)
A SQL Injection vulnerability was found in /admin/edit_student.php in KASHIPARA E-learning Management System Project 1.0 via the cys, un, ln, fn, and id parameters.
0
Attacker Value
Unknown
CVE-2024-50834
Disclosure Date: November 14, 2024 (last updated November 19, 2024)
A SQL Injection was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0 via the firstname and lastname parameters.
0
Attacker Value
Unknown
CVE-2024-50833
Disclosure Date: November 14, 2024 (last updated November 19, 2024)
A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password parameters.
0
Attacker Value
Unknown
CVE-2024-50832
Disclosure Date: November 14, 2024 (last updated November 19, 2024)
A SQL Injection vulnerability was found in /admin/edit_class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.
0
Attacker Value
Unknown
CVE-2024-8001
Disclosure Date: November 13, 2024 (last updated November 20, 2024)
A vulnerability was found in VIWIS LMS 9.11. It has been classified as critical. Affected is an unknown function of the component Print Handler. The manipulation leads to missing authorization. It is possible to launch the attack remotely. A user with the role learner can use the administrative print function with an active session before and after an exam slot to access the entire exam including solutions in the web application. It is recommended to apply a patch to fix this issue.
0
Attacker Value
Unknown
CVE-2024-10470
Disclosure Date: November 09, 2024 (last updated January 06, 2025)
The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The theme is vulnerable even when it is not activated.
0
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2024-6009
Disclosure Date: June 15, 2024 (last updated July 20, 2024)
A vulnerability has been found in itsourcecode Event Calendar 1.0 and classified as critical. Affected by this vulnerability is the function regConfirm/regDelete of the file process.php. The manipulation of the argument userId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-268699.
0