Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2022-4052
Disclosure Date: November 17, 2022 (last updated February 24, 2025)
A vulnerability was found in Student Attendance Management System and classified as critical. This issue affects some unknown processing of the file /Admin/createClass.php. The manipulation of the argument Id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-213845 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-4053
Disclosure Date: November 17, 2022 (last updated February 24, 2025)
A vulnerability was found in Student Attendance Management System. It has been classified as problematic. Affected is an unknown function of the file createClass.php. The manipulation of the argument className leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-213846 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2021-45866
Disclosure Date: March 29, 2022 (last updated February 23, 2025)
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Student Attendance Management System 1.0 via the couse filed in index.php.
0
Attacker Value
Unknown
CVE-2021-45865
Disclosure Date: March 29, 2022 (last updated February 23, 2025)
A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functionality.
0
Attacker Value
Unknown
CVE-2021-45348
Disclosure Date: February 14, 2022 (last updated October 07, 2023)
An Arbitrary File Deletion vulnerability exists in SourceCodester Attendance Management System v1.0 via the csv parameter in admin/pageUploadCSV.php, which can cause a Denial of Service (crash).
0
Attacker Value
Unknown
CVE-2021-44598
Disclosure Date: December 26, 2021 (last updated February 23, 2025)
Attendance Management System 1.0 is affected by a Cross Site Scripting (XSS) vulnerability. The value of the FirstRecord request parameter is copied into the value of an HTML tag attribute which is encapsulated in double quotation marks. The attacker can access the system, by using the XSS-reflected method, and then can store information by injecting the admin account on this system.
0
Attacker Value
Unknown
CVE-2021-44280
Disclosure Date: December 01, 2021 (last updated February 23, 2025)
attendance management system 1.0 is affected by a SQL injection vulnerability in admin/incFunctions.php through the makeSafe function.
0