Show filters
126 Total Results
Displaying 81-90 of 126
Sort by:
Attacker Value
Unknown
CVE-2023-24232
Disclosure Date: February 10, 2023 (last updated February 24, 2025)
A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/product.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter.
0
Attacker Value
Unknown
CVE-2023-24231
Disclosure Date: February 10, 2023 (last updated February 24, 2025)
A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/categories.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Categories Name parameter.
0
Attacker Value
Unknown
CVE-2023-23014
Disclosure Date: January 20, 2023 (last updated February 24, 2025)
Cross Site Scripting (XSS) vulnerability in InventorySystem thru commit e08fbbe17902146313501ed0b5feba81d58f455c (on Apr 23, 2021) via edit_store_name and edit_active inputs in file InventorySystem.php.
0
Attacker Value
Unknown
CVE-2022-31340
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/table_edit_ajax.php.
0
Attacker Value
Unknown
CVE-2022-31339
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
Simple Inventory System v1.0 is vulnerable to SQL Injection via /inventory/login.php.
0
Attacker Value
Unknown
CVE-2022-28993
Disclosure Date: May 20, 2022 (last updated February 23, 2025)
Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.
0
Attacker Value
Unknown
CVE-2022-28991
Disclosure Date: May 20, 2022 (last updated February 23, 2025)
Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files.
0
Attacker Value
Unknown
CVE-2022-30407
Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Pharmacy Sales And Inventory System v1.0 is vulnerable to SQL Injection via /pharmacy-sales-and-inventory-system/manage_user.php?id=.
0
Attacker Value
Unknown
CVE-2021-44321
Disclosure Date: March 04, 2022 (last updated February 23, 2025)
Mini-Inventory-and-Sales-Management-System is affected by Cross Site Request Forgery (CSRF), where an attacker can update/delete items in the inventory. The attacker must be logged into the application create a malicious file for updating the inventory details and items.
0
Attacker Value
Unknown
CVE-2022-22766
Disclosure Date: February 12, 2022 (last updated February 23, 2025)
Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health information (ePHI) or other sensitive information.
0