Show filters
49 Total Results
Displaying 1-10 of 49
Sort by:
Attacker Value
Very High

CVE-2021-42580

Disclosure Date: November 15, 2021 (last updated February 23, 2025)
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated remote command execution.
Attacker Value
Unknown

CVE-2025-1590

Disclosure Date: February 23, 2025 (last updated February 24, 2025)
A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/modules/lesson/index.php of the component List of Lessons Page. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely.
Attacker Value
Unknown

CVE-2025-1589

Disclosure Date: February 23, 2025 (last updated February 24, 2025)
A vulnerability was found in SourceCodester E-Learning System 1.0 and classified as problematic. This issue affects some unknown processing of the file /register.php of the component User Registration Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely.
Attacker Value
Unknown

CVE-2024-12127

Disclosure Date: December 17, 2024 (last updated December 18, 2024)
The Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 0.0.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-54935

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter.
Attacker Value
Unknown

CVE-2024-54933

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.
Attacker Value
Unknown

CVE-2024-54930

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.
Attacker Value
Unknown

CVE-2024-54922

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, lastname, and username parameters.
Attacker Value
Unknown

CVE-2024-54926

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the school_year parameter.
Attacker Value
Unknown

CVE-2024-54920

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the firstname, lastname, and class_id parameters.