Show filters
191 Total Results
Displaying 61-70 of 191
Sort by:
Attacker Value
Unknown

CVE-2023-7058

Disclosure Date: December 22, 2023 (last updated February 25, 2025)
A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument page leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248749 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-48395

Disclosure Date: December 15, 2023 (last updated February 25, 2025)
Kaifa Technology WebITR is an online attendance system, it has insufficient validation for user input within a special function. A remote attacker with regular user privilege can exploit this vulnerability to inject arbitrary SQL commands to read database.
Attacker Value
Unknown

CVE-2023-48394

Disclosure Date: December 15, 2023 (last updated February 25, 2025)
Kaifa Technology WebITR is an online attendance system, its file uploading function does not restrict upload of file with dangerous type. A remote attacker with regular user privilege can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.
Attacker Value
Unknown

CVE-2023-48393

Disclosure Date: December 15, 2023 (last updated February 25, 2025)
Kaifa Technology WebITR is an online attendance system. A remote attacker with regular user privilege can obtain partial sensitive system information from error message.
Attacker Value
Unknown

CVE-2023-48392

Disclosure Date: December 15, 2023 (last updated February 25, 2025)
Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including administrator’s account, to execute login account’s permissions, and obtain relevant information.
Attacker Value
Unknown

CVE-2023-48050

Disclosure Date: December 15, 2023 (last updated February 25, 2025)
SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attendance) v. 13.0 through 16.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the db parameter in the controllers/controllers.py component.
Attacker Value
Unknown

CVE-2023-6771

Disclosure Date: December 13, 2023 (last updated February 25, 2025)
A vulnerability, which was classified as critical, has been found in SourceCodester Simple Student Attendance System 1.0. This issue affects the function save_attendance of the file actions.class.php. The manipulation of the argument sid leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247907.
Attacker Value
Unknown

CVE-2023-6658

Disclosure Date: December 10, 2023 (last updated February 25, 2025)
A vulnerability classified as critical was found in SourceCodester Simple Student Attendance System 1.0. This vulnerability affects unknown code of the file ajax-api.php?action=save_attendance. The manipulation of the argument class_id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-247366 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-6657

Disclosure Date: December 10, 2023 (last updated February 25, 2025)
A vulnerability classified as critical has been found in SourceCodester Simple Student Attendance System 1.0. This affects an unknown part of the file /modals/student_form.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-247365 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-6619

Disclosure Date: December 08, 2023 (last updated February 25, 2025)
A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /modals/class_form.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247256.