SourceCodester Kortex Lite Advocate Office Management System是SourceCodester公司的一个办公室管理系统。 SourceCodester Kortex Lite Advocate Office Management System 1.0版本存在SQL注入漏洞,该漏洞源于/control/forgot_pass.php页面中的username参数包含一个SQL注入问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Advocate Office Management System | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-9295 | 7.3 HIGH | SourceCodester Advocate Office Management System login.php sql injection |
| CVE-2024-9319 | 6.3 MEDIUM | SourceCodester Online Timesheet App delete-timesheet.php sql injection |
| CVE-2024-9318 | 6.3 MEDIUM | SourceCodester Advocate Office Management System activate.php sql injection |
| CVE-2024-9317 | 6.3 MEDIUM | SourceCodester Online Eyewear Shop Master.php delete_category sql injection |
| CVE-2024-9315 | 6.3 MEDIUM | SourceCodester Employee and Visitor Gate Pass Logging System manage_department.php sql inj |
| CVE-2024-9297 | 6.3 MEDIUM | SourceCodester Online Railway Reservation System admin improper authorization |
| CVE-2024-9300 | 4.3 MEDIUM | SourceCodester Online Railway Reservation System Message Us Form contact_us.php cross site |
| CVE-2024-9298 | 4.3 MEDIUM | SourceCodester Online Railway Reservation System Ticket ?page=tickets access control |
| CVE-2024-9299 | 3.5 LOW | SourceCodester Online Railway Reservation System ?page=reserve cross site scripting |
No comments yet