Show filters
239 Total Results
Displaying 61-70 of 239
Sort by:
Attacker Value
Unknown

CVE-2024-7150

Disclosure Date: August 08, 2024 (last updated January 05, 2025)
The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 1.2.57 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0
Attacker Value
Unknown

CVE-2024-41239

Disclosure Date: August 07, 2024 (last updated August 09, 2024)
A Stored Cross Site Scripting (XSS) vulnerability was found in "/smsa/add_class_submit.php" in Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "class_name" parameter field.
Attacker Value
Unknown

CVE-2024-41237

Disclosure Date: August 07, 2024 (last updated August 09, 2024)
A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.
Attacker Value
Unknown

CVE-2024-41242

Disclosure Date: August 07, 2024 (last updated August 09, 2024)
A Reflected Cross Site Scripting (XSS) vulnerability was found in /smsa/student_login.php in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "error" parameter.
Attacker Value
Unknown

CVE-2024-41241

Disclosure Date: August 07, 2024 (last updated August 09, 2024)
A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/admin_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "error" parameter.
Attacker Value
Unknown

CVE-2024-41240

Disclosure Date: August 07, 2024 (last updated August 09, 2024)
A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/teacher_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via the "error" parameter.
Attacker Value
Unknown

CVE-2024-41250

Disclosure Date: August 07, 2024 (last updated August 09, 2024)
An Incorrect Access Control vulnerability was found in /smsa/view_students.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view STUDENT details.
Attacker Value
Unknown

CVE-2024-41245

Disclosure Date: August 07, 2024 (last updated August 09, 2024)
An Incorrect Access Control vulnerability was found in /smsa/view_teachers.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view TEACHER details.
Attacker Value
Unknown

CVE-2024-41244

Disclosure Date: August 07, 2024 (last updated August 09, 2024)
An Incorrect Access Control vulnerability was found in /smsa/view_class.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view CLASS details.
Attacker Value
Unknown

CVE-2024-41243

Disclosure Date: August 07, 2024 (last updated August 09, 2024)
An Incorrect Access Control vulnerability was found in /smsa/view_marks.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view MARKS details.