SourceCodester Online Timesheet App是SourceCodester的一个使用 PHP 和 MySQL 构建的网络应用程序,旨在简化时间管理和任务跟踪。 SourceCodester Online Timesheet App 1.0版本存在SQL注入漏洞,该漏洞源于/endpoint/delete-timesheet.php页面中的timesheet参数包含一个SQL注入问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Online Timesheet App | 1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-9296 | 7.3 HIGH | SourceCodester Advocate Office Management System forgot_pass.php sql injection |
| CVE-2024-9295 | 7.3 HIGH | SourceCodester Advocate Office Management System login.php sql injection |
| CVE-2024-9318 | 6.3 MEDIUM | SourceCodester Advocate Office Management System activate.php sql injection |
| CVE-2024-9317 | 6.3 MEDIUM | SourceCodester Online Eyewear Shop Master.php delete_category sql injection |
| CVE-2024-9315 | 6.3 MEDIUM | SourceCodester Employee and Visitor Gate Pass Logging System manage_department.php sql inj |
| CVE-2024-9297 | 6.3 MEDIUM | SourceCodester Online Railway Reservation System admin improper authorization |
| CVE-2024-9300 | 4.3 MEDIUM | SourceCodester Online Railway Reservation System Message Us Form contact_us.php cross site |
| CVE-2024-9298 | 4.3 MEDIUM | SourceCodester Online Railway Reservation System Ticket ?page=tickets access control |
| CVE-2024-9299 | 3.5 LOW | SourceCodester Online Railway Reservation System ?page=reserve cross site scripting |
No comments yet