Church Management System Project
Church Management System Project Church Management System: vulnerabilidades y CVE
Church Management System Project Church Management System tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-45328 | Alta (7.2) | 0.76% | — | 30 nov 2022 | Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_members.php. |
| CVE-2022-41406 | Alta (7.2) | 1.2% | — | 12 oct 2022 | An arbitrary file upload vulnerability in the /admin/admin_pic.php component of Church Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. |
| CVE-2022-38595 | Alta (7.2) | 0.88% | — | 15 sept 2022 | Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_user.php. |
| CVE-2022-38594 | Alta (7.2) | 0.88% | — | 15 sept 2022 | Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_visitor.php. |
| CVE-2022-38605 | Alta (7.2) | 1.00% | — | 12 sept 2022 | Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_event.php. |
| CVE-2022-2680 | Alta (8.8) | 0.75% | — | 5 ago 2022 | A vulnerability classified as critical has been found in SourceCodester Church Management System 1.0. Affected is an unknown function of the file /login.php. The manipulation of the argument username with the input ' OR… |
| CVE-2021-41661 | Crítica (9.8) | 1.3% | — | 13 jun 2022 | Church Management System version 1.0 is affected by a SQL anjection vulnerability through creating a user with a PHP file as an avatar image, which is accessible through the /uploads directory. This can lead to RCE on… |
| CVE-2021-41643 | Crítica (9.8) | 4.6% | — | 29 oct 2021 | Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field. |