Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2022-43362

Disclosure Date: November 01, 2022 (last updated February 24, 2025)
Senayan Library Management System v9.4.2 was discovered to contain a SQL injection vulnerability via the collType parameter at loan_by_class.php.
Attacker Value
Unknown

CVE-2022-43361

Disclosure Date: November 01, 2022 (last updated February 24, 2025)
Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component pop_chart.php.
Attacker Value
Unknown

CVE-2022-38292

Disclosure Date: September 12, 2022 (last updated February 24, 2025)
SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the components /bibliography/marcsru.php and /bibliography/z3950sru.php.
Attacker Value
Unknown

CVE-2022-38291

Disclosure Date: September 12, 2022 (last updated February 24, 2025)
SLiMS Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Search function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search bar.
Attacker Value
Unknown

CVE-2021-45794

Disclosure Date: March 17, 2022 (last updated February 23, 2025)
Slims9 Bulian 9.4.2 is affected by SQL injection in /admin/modules/system/backup.php. User data can be obtained.
Attacker Value
Unknown

CVE-2021-45793

Disclosure Date: March 17, 2022 (last updated February 23, 2025)
Slims9 Bulian 9.4.2 is affected by SQL injection in lib/comment.inc.php. User data can be obtained.
Attacker Value
Unknown

CVE-2021-45792

Disclosure Date: March 17, 2022 (last updated February 23, 2025)
Slims9 Bulian 9.4.2 is affected by Cross Site Scripting (XSS) in /admin/modules/system/custom_field.php.