Attendance and Payroll System是oretnom23个人开发者的一个使用 PHP/MySQLi 源代码的考勤和工资系统。 Attendance and Payroll System 1.0版本存在代码问题漏洞,该漏洞源于/marimar/guest/update.php页面中的image参数包含一个不受限制的文件上传漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Attendance and Payroll System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-10422 | 6.3 MEDIUM | SourceCodester Attendance and Payroll System overtime_add.php sql injection |
| CVE-2024-10421 | 6.3 MEDIUM | SourceCodester Attendance and Payroll System overtime_row.php sql injection |
| CVE-2024-10413 | 6.3 MEDIUM | SourceCodester Online Hotel Reservation System update.php upload unrestricted upload |
| CVE-2024-10411 | 6.3 MEDIUM | SourceCodester Online Hotel Reservation System controller.php doCheckout sql injection |
| CVE-2024-10410 | 6.3 MEDIUM | SourceCodester Online Hotel Reservation System controller.php upload unrestricted upload |
No comments yet