Online Student Admission System是一个在线学生入学系统。用于将机构的所有入学前后活动计算机化。 Online Student Admission System存在跨站脚本漏洞,该漏洞源于其学生用户界面edit-profile.php的未知功能对用户输入特殊字符串的操作会导致跨站脚本。该攻击方法已经被公开并且可以由远程发起,存在被利用的风险。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Online Student Admission System | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-2674 | 7.3 HIGH | SourceCodester Best Fee Management System admin_class.php login sql injection |
| CVE-2022-2665 | 6.3 MEDIUM | SourceCodester Simple E-Learning System classroom.php sql injection |
| CVE-2022-2667 | 6.3 MEDIUM | SourceCodester Loan Management System delete_lplan.php sql injection |
| CVE-2022-2671 | 6.3 MEDIUM | SourceCodester Garage Management System removeUser.php sql injection |
| CVE-2022-2672 | 6.3 MEDIUM | SourceCodester Garage Management System createUser.php sql injection |
| CVE-2022-2676 | 6.3 MEDIUM | SourceCodester Electronic Medical Records System POST Request sql injection |
| CVE-2022-2677 | 6.3 MEDIUM | SourceCodester Apartment Visitor Management System index.php sql injection |
| CVE-2022-2678 | 6.3 MEDIUM | SourceCodester Alphaware Simple E-Commerce System Background Management Page admin_feature |
| CVE-2022-2679 | 6.3 MEDIUM | SourceCodester Interview Management System viewReport.php sql injection |
| CVE-2022-2680 | 6.3 MEDIUM | SourceCodester Church Management System login.php sql injection |
| CVE-2022-2682 | 3.5 LOW | SourceCodester Alphaware Simple E-Commerce System stockin.php cross site scripting |
| CVE-2022-2683 | 3.5 LOW | SourceCodester Simple Food Ordering System login.php cross site scripting |
| CVE-2022-2684 | 3.5 LOW | SourceCodester Apartment Visitor Management System manage-apartment.php cross site scripti |
| CVE-2022-2685 | 3.5 LOW | SourceCodester Interview Management System addQuestion.php cross site scripting |
No comments yet