Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2022-39054

Disclosure Date: September 15, 2022 (last updated October 08, 2023)
Cowell enterprise travel management system has insufficient filtering for special characters within web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.
Attacker Value
Unknown

CVE-2022-30842

Disclosure Date: May 24, 2022 (last updated February 23, 2025)
Covid-19 Travel Pass Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /ctpms/classes/Users.php?f=save, firstname.
Attacker Value
Unknown

CVE-2022-30838

Disclosure Date: May 24, 2022 (last updated February 23, 2025)
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=update_application_status
Attacker Value
Unknown

CVE-2022-30417

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via ctpms/admin/?page=user/manage_user&id=.
Attacker Value
Unknown

CVE-2022-30415

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/applications/update_status.php?id=.
Attacker Value
Unknown

CVE-2022-30414

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/?page=applications/view_application&id=.
Attacker Value
Unknown

CVE-2022-30413

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=delete_application.
Attacker Value
Unknown

CVE-2022-30412

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/individuals/update_status.php?id=.
Attacker Value
Unknown

CVE-2022-30411

Disclosure Date: May 13, 2022 (last updated February 23, 2025)
Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/?page=individuals/view_individual&id=.
Attacker Value
Unknown

CVE-2022-30408

Disclosure Date: May 13, 2022 (last updated October 07, 2023)
Covid-19 Travel Pass Management System v1.0 is vulnerable to file deletion via /ctpms/classes/Master.php?f=delete_img.