Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2024-9660
Disclosure Date: November 23, 2024 (last updated January 05, 2025)
The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_load_documets_new() and mj_smgt_load_documets() functions in all versions up to, and including, 91.5.0. This makes it possible for authenticated attackers, with Student-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
0
Attacker Value
Unknown
CVE-2024-9659
Disclosure Date: November 23, 2024 (last updated January 05, 2025)
The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_user_avatar_image_upload() function in all versions up to, and including, 91.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
0
Attacker Value
Unknown
CVE-2017-14848
Disclosure Date: October 03, 2017 (last updated November 26, 2024)
WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.
0
Attacker Value
Unknown
CVE-2017-14847
Disclosure Date: September 28, 2017 (last updated November 26, 2024)
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
0
Attacker Value
Unknown
CVE-2017-14841
Disclosure Date: September 28, 2017 (last updated November 26, 2024)
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.
0
Attacker Value
Unknown
CVE-2017-14843
Disclosure Date: September 28, 2017 (last updated November 26, 2024)
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
0
Attacker Value
Unknown
CVE-2017-14846
Disclosure Date: September 28, 2017 (last updated November 26, 2024)
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
0
Attacker Value
Unknown
CVE-2017-14844
Disclosure Date: September 28, 2017 (last updated November 26, 2024)
Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.
0
Attacker Value
Unknown
CVE-2017-14845
Disclosure Date: September 28, 2017 (last updated November 26, 2024)
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
0
Attacker Value
Unknown
CVE-2017-14842
Disclosure Date: September 28, 2017 (last updated November 26, 2024)
Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.
0