Prison Management System是Carlo Montero个人开发者的一个监狱管理系统。 Prison Management System 1.0 版本存在代码问题漏洞,该漏洞源于 /Admin/add-admin.php of the component Avatar Handler 文件的 avatar 参数可以进行不受限制的文件上传。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Prison Management System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-3438 | 7.3 HIGH | SourceCodester Prison Management System login.php sql injection |
| CVE-2024-3439 | 7.3 HIGH | SourceCodester Prison Management System login.php sql injection |
| CVE-2024-3441 | 6.3 MEDIUM | SourceCodester Prison Management System edit-profile.php sql injection |
| CVE-2024-3442 | 6.3 MEDIUM | SourceCodester Prison Management System delete_leave.php sql injection |
| CVE-2024-3445 | 6.3 MEDIUM | SourceCodester Laundry Management System laporan_filter sql injection |
| CVE-2024-3464 | 6.3 MEDIUM | SourceCodester Laundry Management System Pelanggan.php laporan_filter sql injection |
| CVE-2024-3465 | 6.3 MEDIUM | SourceCodester Laundry Management System Transaki.php laporan_filter sql injection |
| CVE-2024-3466 | 5.5 MEDIUM | SourceCodester Laundry Management System Pengeluaran.php laporan_filter sql injection |
| CVE-2024-3440 | 4.7 MEDIUM | SourceCodester Prison Management System edit_profile.php sql injection |
| CVE-2024-3443 | 3.5 LOW | SourceCodester Prison Management System apply_leave.php cross site scripting |
| CVE-2024-3463 | 3.5 LOW | SourceCodester Laundry Management System edit cross site scripting |
No comments yet