Simple E-Learning System是Carlo Montero个人开发者的一个简单的电子学习系统。 Simple E-Learning System存在跨站脚本漏洞,该漏洞源于文件/claire_blake的未知代码受到影响,对参数Bio的操作会导致跨站脚本。攻击可以远程发起,该漏洞利用已向公众披露并可能被使用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Simple E-Learning System | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-2702 | 7.3 HIGH | SourceCodester Company Website CMS Cookie site-settings.php access control |
| CVE-2022-2699 | 6.3 MEDIUM | SourceCodester Simple E-Learning System claire_blake sql injection |
| CVE-2022-2703 | 6.3 MEDIUM | SourceCodester Gym Management System Exercises Module sql injection |
| CVE-2022-2705 | 6.3 MEDIUM | SourceCodester Simple Student Information System manage_department.php sql injection |
| CVE-2022-2706 | 6.3 MEDIUM | SourceCodester Online Class and Exam Scheduling System class_sched.php sql injection |
| CVE-2022-2707 | 6.3 MEDIUM | SourceCodester Online Class and Exam Scheduling System faculty_sched.php sql injection |
| CVE-2022-2708 | 5.5 MEDIUM | SourceCodester Gym Management System login.php sql injection |
| CVE-2022-2700 | 4.7 MEDIUM | SourceCodester Gym Management System GET Parameter sql injection |
| CVE-2022-2704 | 4.3 MEDIUM | SourceCodester Simple E-Learning System downloadFiles.php information disclosure |
No comments yet