Show filters
31 Total Results
Displaying 21-30 of 31
Sort by:
Attacker Value
Unknown

CVE-2024-2155

Disclosure Date: March 04, 2024 (last updated March 04, 2024)
A vulnerability was found in SourceCodester Best POS Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file index.php. The manipulation of the argument page leads to file inclusion. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-255587.
0
Attacker Value
Unknown

CVE-2024-2145

Disclosure Date: March 03, 2024 (last updated March 04, 2024)
A vulnerability was found in SourceCodester Online Mobile Management Store 1.0. It has been classified as problematic. Affected is an unknown function of the file /endpoint/update-tracker.php. The manipulation of the argument firstname leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-255498 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown

CVE-2024-2075

Disclosure Date: March 01, 2024 (last updated March 02, 2024)
A vulnerability was found in SourceCodester Daily Habit Tracker 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /endpoint/update-tracker.php. The manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-255391.
0
Attacker Value
Unknown

CVE-2023-3694

Disclosure Date: July 17, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as critical, has been found in SourceCodester House Rental and Property Listing 1.0. This issue affects some unknown processing of the file index.php. The manipulation of the argument keywords/location leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-234245 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2021-44244

Disclosure Date: January 20, 2022 (last updated February 23, 2025)
An SQL Injection vulnerabiity exists in Sourcecodester Logistic Hub Parcel's Management System 1.0 via the username parameter in login.php.
Attacker Value
Unknown

CVE-2021-44090

Disclosure Date: January 20, 2022 (last updated February 23, 2025)
An SQL Injection vulnerability exists in Sourcecodester Online Reviewer System 1.0 via the password parameter.
Attacker Value
Unknown

CVE-2021-41728

Disclosure Date: October 28, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester News247 CMS 1.0 via the search function in articles.
Attacker Value
Unknown

CVE-2020-24932

Disclosure Date: October 27, 2021 (last updated February 23, 2025)
An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php.
Attacker Value
Unknown

CVE-2019-18417

Disclosure Date: October 24, 2019 (last updated November 27, 2024)
Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can result in code execution. The issue occurs because the application fails to adequately sanitize user-supplied input, e.g., "add a new food" allows .php files.
Attacker Value
Unknown

CVE-2019-18414

Disclosure Date: October 24, 2019 (last updated November 27, 2024)
Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code or adding a staff entry via a crafted HTML page.