Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2024-9660

Disclosure Date: November 23, 2024 (last updated January 05, 2025)
The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_load_documets_new() and mj_smgt_load_documets() functions in all versions up to, and including, 91.5.0. This makes it possible for authenticated attackers, with Student-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
0
Attacker Value
Unknown

CVE-2024-9659

Disclosure Date: November 23, 2024 (last updated January 05, 2025)
The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_user_avatar_image_upload() function in all versions up to, and including, 91.5.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
0
Attacker Value
Unknown

CVE-2017-14848

Disclosure Date: October 03, 2017 (last updated November 26, 2024)
WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.
Attacker Value
Unknown

CVE-2017-14847

Disclosure Date: September 28, 2017 (last updated November 26, 2024)
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
0
Attacker Value
Unknown

CVE-2017-14841

Disclosure Date: September 28, 2017 (last updated November 26, 2024)
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.
0
Attacker Value
Unknown

CVE-2017-14843

Disclosure Date: September 28, 2017 (last updated November 26, 2024)
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
0
Attacker Value
Unknown

CVE-2017-14846

Disclosure Date: September 28, 2017 (last updated November 26, 2024)
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
0
Attacker Value
Unknown

CVE-2017-14844

Disclosure Date: September 28, 2017 (last updated November 26, 2024)
Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.
0
Attacker Value
Unknown

CVE-2017-14845

Disclosure Date: September 28, 2017 (last updated November 26, 2024)
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
0
Attacker Value
Unknown

CVE-2017-14842

Disclosure Date: September 28, 2017 (last updated November 26, 2024)
Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.
0