Show filters
126 Total Results
Displaying 51-60 of 126
Sort by:
Attacker Value
Unknown

CVE-2023-46450

Disclosure Date: October 26, 2023 (last updated February 25, 2025)
Sourcecodester Free and Open Source inventory management system 1.0 is vulnerable to Cross Site Scripting (XSS) via the Add supplier function.
Attacker Value
Unknown

CVE-2023-46449

Disclosure Date: October 26, 2023 (last updated February 25, 2025)
Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.
Attacker Value
Unknown

CVE-2023-39712

Disclosure Date: September 08, 2023 (last updated February 25, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Put section.
Attacker Value
Unknown

CVE-2023-39711

Disclosure Date: September 07, 2023 (last updated February 25, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put section.
Attacker Value
Unknown

CVE-2023-4749

Disclosure Date: September 04, 2023 (last updated February 25, 2025)
A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file index.php. The manipulation of the argument page leads to file inclusion. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-238638 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-39714

Disclosure Date: September 01, 2023 (last updated February 25, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add New Member section.
Attacker Value
Unknown

CVE-2023-39710

Disclosure Date: September 01, 2023 (last updated February 25, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Customer section.
Attacker Value
Unknown

CVE-2023-39709

Disclosure Date: August 28, 2023 (last updated February 25, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name, Address, and Company parameters under the Add Member section.
Attacker Value
Unknown

CVE-2023-39708

Disclosure Date: August 28, 2023 (last updated February 25, 2025)
A stored cross-site scripting (XSS) vulnerability in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Add New parameter under the New Buy section.
Attacker Value
Unknown

CVE-2023-4558

Disclosure Date: August 27, 2023 (last updated February 25, 2025)
A vulnerability classified as critical was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file staff_data.php. The manipulation of the argument columns[0][data] leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-238159.