Show filters
30 Total Results
Displaying 21-30 of 30
Sort by:
Attacker Value
Unknown

CVE-2024-50835

Disclosure Date: November 14, 2024 (last updated November 19, 2024)
A SQL Injection vulnerability was found in /admin/edit_student.php in KASHIPARA E-learning Management System Project 1.0 via the cys, un, ln, fn, and id parameters.
Attacker Value
Unknown

CVE-2024-50834

Disclosure Date: November 14, 2024 (last updated November 19, 2024)
A SQL Injection was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0 via the firstname and lastname parameters.
Attacker Value
Unknown

CVE-2024-50833

Disclosure Date: November 14, 2024 (last updated November 19, 2024)
A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password parameters.
Attacker Value
Unknown

CVE-2024-50832

Disclosure Date: November 14, 2024 (last updated November 19, 2024)
A SQL Injection vulnerability was found in /admin/edit_class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.
Attacker Value
Unknown

CVE-2024-6009

Disclosure Date: June 15, 2024 (last updated July 20, 2024)
A vulnerability has been found in itsourcecode Event Calendar 1.0 and classified as critical. Affected by this vulnerability is the function regConfirm/regDelete of the file process.php. The manipulation of the argument userId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-268699.
Attacker Value
Unknown

CVE-2024-5588

Disclosure Date: June 02, 2024 (last updated February 12, 2025)
A vulnerability was found in itsourcecode Learning Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file processscore.php. The manipulation of the argument LessonID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-266839.
Attacker Value
Unknown

CVE-2024-5519

Disclosure Date: May 30, 2024 (last updated February 12, 2025)
A vulnerability classified as critical was found in ItsourceCode Learning Management System Project In PHP 1.0. This vulnerability affects unknown code of the file login.php. The manipulation of the argument user_email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-266590 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2021-25200

Disclosure Date: July 30, 2021 (last updated February 23, 2025)
Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\student_avatar.php.
Attacker Value
Unknown

CVE-2021-25201

Disclosure Date: July 23, 2021 (last updated February 23, 2025)
SQL injection vulnerability in Learning Management System v 1.0 allows remote attackers to execute arbitrary SQL statements through the id parameter to obtain sensitive database information.
Attacker Value
Unknown

CVE-2019-10219

Disclosure Date: November 08, 2019 (last updated November 08, 2023)
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.