Show filters
23 Total Results
Displaying 1-10 of 23
Sort by:
Attacker Value
Unknown
CVE-2024-37856
Disclosure Date: July 29, 2024 (last updated February 26, 2025)
Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the first, last, middle name fields in the User Profile page.
0
Attacker Value
Unknown
CVE-2023-33677
Disclosure Date: March 06, 2024 (last updated February 26, 2025)
Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*".
0
Attacker Value
Unknown
CVE-2023-38965
Disclosure Date: November 03, 2023 (last updated February 25, 2025)
Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.
0
Attacker Value
Unknown
CVE-2023-5018
Disclosure Date: September 17, 2023 (last updated February 25, 2025)
A vulnerability classified as critical has been found in SourceCodester Lost and Found Information System 1.0. This affects an unknown part of the file /classes/Master.php?f=save_category of the component POST Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-239859.
0
Attacker Value
Unknown
CVE-2023-36159
Disclosure Date: August 04, 2023 (last updated February 25, 2025)
Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields on the Create User page.
0
Attacker Value
Unknown
CVE-2023-3850
Disclosure Date: July 23, 2023 (last updated February 25, 2025)
A vulnerability has been found in SourceCodester Lost and Found Information System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=delete_category of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The identifier VDB-235201 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-3680
Disclosure Date: July 15, 2023 (last updated February 25, 2025)
A vulnerability classified as critical has been found in SourceCodester Lost and Found Information System 1.0. This affects an unknown part of the file /classes/Master.php?f=save_item of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The identifier VDB-234225 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-3679
Disclosure Date: July 15, 2023 (last updated February 25, 2025)
A vulnerability was found in SourceCodester Lost and Found Information System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=save_inquiry of the component HTTP POST Request Handler. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The identifier of this vulnerability is VDB-234224.
0
Attacker Value
Unknown
CVE-2023-33592
Disclosure Date: June 28, 2023 (last updated February 25, 2025)
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information.
0
Attacker Value
Unknown
CVE-2023-3177
Disclosure Date: June 09, 2023 (last updated February 25, 2025)
A vulnerability has been found in SourceCodester Lost and Found Information System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file admin\inquiries\view_inquiry.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-231151.
0