Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2024-7681

Disclosure Date: August 12, 2024 (last updated August 16, 2024)
A vulnerability was found in code-projects College Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php of the component Login Page. The manipulation of the argument email/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2022-39180

Disclosure Date: November 17, 2022 (last updated October 26, 2023)
College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in the login.php page
Attacker Value
Unknown

CVE-2022-39179

Disclosure Date: November 17, 2022 (last updated October 26, 2023)
College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious code via student.php file.
Attacker Value
Unknown

CVE-2022-32420

Disclosure Date: July 01, 2022 (last updated October 07, 2023)
College Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /College/admin/teacher.php. This vulnerability is exploited via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-30404

Disclosure Date: May 13, 2022 (last updated October 07, 2023)
College Management System v1.0 is vulnerable to SQL Injection via /College_Management_System/admin/display-teacher.php?teacher_id=.
Attacker Value
Unknown

CVE-2022-28079

Disclosure Date: May 05, 2022 (last updated October 07, 2023)
College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.
Attacker Value
Unknown

CVE-2022-26615

Disclosure Date: April 05, 2022 (last updated October 07, 2023)
A cross-site scripting (XSS) vulnerability in College Website Content Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User Profile Name text fields.
Attacker Value
Unknown

CVE-2022-1078

Disclosure Date: March 29, 2022 (last updated October 07, 2023)
A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. Affected is the file /cwms/admin/?page=articles/view_article/. The manipulation of the argument id with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc with an unknown input leads to sql injection. It is possible to launch the attack remotely and without authentication.
Attacker Value
Unknown

CVE-2022-1075

Disclosure Date: March 29, 2022 (last updated October 07, 2023)
A vulnerability was found in College Website Management System 1.0 and classified as problematic. Affected by this issue is the file /cwms/classes/Master.php?f=save_contact of the component Contact Handler. The manipulation leads to persistent cross site scripting. The attack may be launched remotely and requires authentication.
Attacker Value
Unknown

CVE-2020-25409

Disclosure Date: May 24, 2021 (last updated November 28, 2024)
Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters.