Code-Projects Chat System是Code-Projects开源的一个聊天系统。 code-projects Chat System 1.0版本存在跨站脚本漏洞,该漏洞源于Chat Interface组件中/admin/send_message.php文件对参数msg操作不当,可能导致跨站脚本。攻击者可能远程发起攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| code-projects | Chat System | 1.0 |
cpe:2.3:a:code-projects:chat_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7070 | 7.3 HIGH | code-projects Inventory Management System Login sql injection |
| CVE-2026-7131 | 7.3 HIGH | code-projects Online Lot Reservation System loginuser.php sql injection |
| CVE-2026-7091 | 6.3 MEDIUM | code-projects Invoice System in Laravel User Management user improper authorization |
| CVE-2026-7092 | 6.3 MEDIUM | code-projects Invoice System in Laravel Profile profile improper authorization |
| CVE-2026-7093 | 6.3 MEDIUM | code-projects Invoice System in Laravel Invoice Endpoint invoice improper authorization |
| CVE-2026-7107 | 6.3 MEDIUM | code-projects Invoice System in Laravel company unrestricted upload |
| CVE-2026-7114 | 6.3 MEDIUM | code-projects Employee Management System edit.php sql injection |
| CVE-2026-7115 | 6.3 MEDIUM | code-projects Employee Management System delete.php sql injection |
| CVE-2026-7118 | 6.3 MEDIUM | code-projects Employee Management System cancel.php sql injection |
| CVE-2026-7117 | 6.3 MEDIUM | code-projects Employee Management System approve.php sql injection |
| CVE-2026-7132 | 5.3 MEDIUM | code-projects Online Lot Reservation System download.php readfile path traversal |
| CVE-2026-7109 | 5.3 MEDIUM | code-projects Invoice System in Laravel API Endpoint item improper authorization |
| CVE-2026-7134 | 4.7 MEDIUM | code-projects Online Lot Reservation System edithousepic.php unrestricted upload |
| CVE-2026-7133 | 4.7 MEDIUM | code-projects Online Lot Reservation System activity.php unrestricted upload |
| CVE-2026-7089 | 4.3 MEDIUM | code-projects Home Service System Appointment Booking booking.php cross site scripting |
| CVE-2026-7116 | 4.3 MEDIUM | code-projects Employee Management System mark.php cross site scripting |
| CVE-2026-7108 | 4.3 MEDIUM | code-projects Invoice System in Laravel cross-site request forgery |
| CVE-2026-7095 | 4.3 MEDIUM | code-projects Employee Management System edit.php cross site scripting |
| CVE-2026-7103 | 3.7 LOW | code-projects Chat System MD5 Hash update_user.php weak hash |
| CVE-2026-7110 | 3.5 LOW | code-projects Invoice System in Laravel item cross site scripting |
No comments yet