Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2023-0675

Disclosure Date: February 04, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as critical, was found in Calendar Event Management System 2.3.0. This affects an unknown part. The manipulation of the argument start/end leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-220197 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-0663

Disclosure Date: February 03, 2023 (last updated October 08, 2023)
A vulnerability was found in Calendar Event Management System 2.3.0. It has been rated as critical. This issue affects some unknown processing of the component Login Page. The manipulation of the argument name/pwd leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-220175.
Attacker Value
Unknown

CVE-2022-1102

Disclosure Date: January 07, 2023 (last updated October 08, 2023)
A vulnerability classified as problematic has been found in SourceCodester Royale Event Management System 1.0. Affected is an unknown function of the file /royal_event/companyprofile.php. The manipulation of the argument companyname/regno/companyaddress/companyemail leads to cross site scripting. It is possible to launch the attack remotely. VDB-195786 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-1101

Disclosure Date: January 07, 2023 (last updated October 08, 2023)
A vulnerability was found in SourceCodester Royale Event Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /royal_event/userregister.php. The manipulation leads to improper authentication. The attack may be initiated remotely. The identifier VDB-195785 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-38323

Disclosure Date: September 15, 2022 (last updated October 08, 2023)
Event Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /Royal_Event/update_image.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
Attacker Value
Unknown

CVE-2022-28080

Disclosure Date: May 05, 2022 (last updated February 23, 2025)
Royal Event Management System v1.0 was discovered to contain a SQL injection vulnerability via the todate parameter.
Attacker Value
Unknown

CVE-2018-18795

Disclosure Date: November 16, 2018 (last updated November 27, 2024)
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
0
Attacker Value
Unknown

CVE-2018-18794

Disclosure Date: November 16, 2018 (last updated November 27, 2024)
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
0
Attacker Value
Unknown

CVE-2018-18793

Disclosure Date: November 16, 2018 (last updated November 27, 2024)
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
0