Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown

CVE-2024-13012

Disclosure Date: December 29, 2024 (last updated February 19, 2025)
A vulnerability, which was classified as problematic, has been found in code-projects Hostel Management System 1.0. This issue affects some unknown processing of the file /admin/registration.php. The manipulation of the argument fname/mname/lname leads to cross site scripting. The attack may be initiated remotely.
Attacker Value
Unknown

CVE-2024-12790

Disclosure Date: December 19, 2024 (last updated December 20, 2024)
A vulnerability was found in code-projects Hostel Management Site 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file room-details.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown

CVE-2024-3753

Disclosure Date: July 13, 2024 (last updated July 13, 2024)
The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
0
Attacker Value
Unknown

CVE-2024-4314

Disclosure Date: May 14, 2024 (last updated January 05, 2025)
The Hostel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5.3. This is due to missing or incorrect nonce validation when managing rooms. This makes it possible for unauthenticated attackers to create and delete rooms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown

CVE-2024-2482

Disclosure Date: March 15, 2024 (last updated January 24, 2025)
A vulnerability has been found in Surya2Developer Hostel Management Service 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /check_availability.php of the component HTTP POST Request Handler. The manipulation of the argument oldpassword leads to observable response discrepancy. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-256891.
Attacker Value
Unknown

CVE-2024-2481

Disclosure Date: March 15, 2024 (last updated January 24, 2025)
A vulnerability, which was classified as critical, was found in Surya2Developer Hostel Management System 1.0. Affected is an unknown function of the file /admin/manage-students.php. The manipulation of the argument del leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-256890 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-36939

Disclosure Date: July 10, 2023 (last updated November 15, 2023)
Cross-Site Scripting (XSS) vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the search booking field.
Attacker Value
Unknown

CVE-2023-36375

Disclosure Date: July 10, 2023 (last updated November 15, 2023)
Cross Site Scripting vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the Guardian name, Guardian relation, complimentary address, city, permanent address, and city parameters in the Book Hostel & Room Details page.
Attacker Value
Unknown

CVE-2023-36376

Disclosure Date: July 10, 2023 (last updated November 15, 2023)
Cross-Site Scripting (XSS) vulnerability in Hostel Management System v.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the add course section.
Attacker Value
Unknown

CVE-2023-34647

Disclosure Date: June 28, 2023 (last updated November 15, 2023)
PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).