Show filters
35 Total Results
Displaying 21-30 of 35
Sort by:
Attacker Value
Unknown

CVE-2023-1179

Disclosure Date: March 05, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. Affected is an unknown function of the component Add Supplier Handler. The manipulation of the argument company_name/province/city/phone_number leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-222330 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-1131

Disclosure Date: March 01, 2023 (last updated February 24, 2025)
A vulnerability has been found in SourceCodester Computer Parts Sales and Inventory System 1.0 and classified as problematic. This vulnerability affects unknown code of the file customer.php. The manipulation of the argument FIRST_NAME/LAST_NAME/PHONE_NUMBER leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-222106 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-1130

Disclosure Date: March 01, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as critical, was found in SourceCodester Computer Parts Sales and Inventory System 1.0. This affects an unknown part of the file processlogin. The manipulation of the argument user leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222105 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-24234

Disclosure Date: February 10, 2023 (last updated February 24, 2025)
A stored cross-site scripting (XSS) vulnerability in the component php-inventory-management-system/brand.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Brand Name parameter.
Attacker Value
Unknown

CVE-2023-24233

Disclosure Date: February 10, 2023 (last updated February 24, 2025)
A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/orders.php?o=add of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Client Name parameter.
Attacker Value
Unknown

CVE-2023-24232

Disclosure Date: February 10, 2023 (last updated February 24, 2025)
A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/product.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter.
Attacker Value
Unknown

CVE-2023-24231

Disclosure Date: February 10, 2023 (last updated February 24, 2025)
A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/categories.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Categories Name parameter.
Attacker Value
Unknown

CVE-2023-23014

Disclosure Date: January 20, 2023 (last updated February 24, 2025)
Cross Site Scripting (XSS) vulnerability in InventorySystem thru commit e08fbbe17902146313501ed0b5feba81d58f455c (on Apr 23, 2021) via edit_store_name and edit_active inputs in file InventorySystem.php.
Attacker Value
Unknown

CVE-2022-31340

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php.
Attacker Value
Unknown

CVE-2022-31339

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/login.php.