Security
Headlines
HeadlinesLatestCVEs

Tag

#php

CVE-2022-32401: BugBounty/cve-2022-32401.md at main · Dyrandy/BugBounty

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_privilege.php:4

CVE
#sql#vulnerability#php
CVE-2022-32391: BugBounty/cve-2022-32391.md at main · Dyrandy/BugBounty

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/view_action.php:4

CVE-2022-32396: BugBounty/cve-2022-32396.md at main · Dyrandy/BugBounty

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/manage_visit.php:4

CVE-2022-32400: BugBounty/cve-2022-32400.md at main · Dyrandy/BugBounty

Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/user/manage_user.php:4.

CVE-2022-32987: Simple Bakery Shop Management System in PHP MySQL

Multiple cross-site scripting (XSS) vulnerabilities in /bsms/?page=manage_account of Simple Bakery Shop Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username or Full Name fields.

CVE-2022-34328: GitHub - jenaye/PMB

PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.

CVE-2021-40956: SQL injection exists in the LaiKetui menu management function · Issue #13 · bettershop/LaikeTui

LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained.

CVE-2021-40954: Any file upload exists at the background plug-in · Issue #11 · bettershop/LaikeTui

Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary code.

CVE-2022-31361: Security Advisory: Docebo Community Edition <= 4.0.5 - Swascan

** UNSUPPORTED WHEN ASSIGNED ** Docebo Community Edition v4.0.5 and below was discovered to contain a SQL injection vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2021-29055

Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Firtstname parameter to the Update Account form in student_profile.php.