Show filters
25 Total Results
Displaying 21-25 of 25
Sort by:
Attacker Value
Unknown
CVE-2022-2293
Disclosure Date: July 12, 2022 (last updated October 07, 2023)
A vulnerability classified as problematic was found in SourceCodester Simple Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ci_ssms/index.php/orders/create. The manipulation of the argument customer_name with the input <script>alert("XSS")</script> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2021-44321
Disclosure Date: March 04, 2022 (last updated February 23, 2025)
Mini-Inventory-and-Sales-Management-System is affected by Cross Site Request Forgery (CSRF), where an attacker can update/delete items in the inventory. The attacker must be logged into the application create a malicious file for updating the inventory details and items.
0
Attacker Value
Unknown
CVE-2021-36560
Disclosure Date: November 02, 2021 (last updated February 23, 2025)
Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of the admin.
0
Attacker Value
Unknown
CVE-2021-36623
Disclosure Date: August 03, 2021 (last updated February 23, 2025)
Arbitrary File Upload in Sourcecodester Phone Shop Sales Management System 1.0 enables RCE.
0
Attacker Value
Unknown
CVE-2021-35337
Disclosure Date: July 01, 2021 (last updated February 22, 2025)
Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any attacker will be able to see the invoices of different users by changing the id parameter.
0