College Management System Project
College Management System Project College Management System: vulnerabilidades y CVE
College Management System Project College Management System tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-7681 | Media (6.9) | 0.73% | — | 12 ago 2024 | A vulnerability was found in code-projects College Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php of the component Login Page. The manipulation of… |
| CVE-2022-39180 | Crítica (9.8) | 0.64% | — | 17 nov 2022 | College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in the login.php page |
| CVE-2022-39179 | Alta (7.2) | 1.1% | — | 17 nov 2022 | College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious… |
| CVE-2022-32420 | Alta (8.8) | 20% | — | 1 jul 2022 | College Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /College/admin/teacher.php. This vulnerability is exploited via a crafted PHP file. |
| CVE-2022-30404 | Alta (7.2) | 0.81% | — | 13 may 2022 | College Management System v1.0 is vulnerable to SQL Injection via /College_Management_System/admin/display-teacher.php?teacher_id=. |
| CVE-2022-28079 | Alta (8.8) | 29% | — | 5 may 2022 | College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter. |
| CVE-2020-25409 | Crítica (9.8) | 1.6% | — | 24 may 2021 | Projectsworlds College Management System Php 1.0 is vulnerable to SQL injection issues over multiple parameters. |
| CVE-2020-25408 | Media (6.5) | 0.78% | — | 24 may 2021 | A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows a remote attacker to modify, delete, or make a new entry of the student, faculty, teacher, subject,… |
| CVE-2020-26051 | Crítica (9.8) | 2.4% | — | 8 feb 2021 | College Management System Php 1.0 suffers from SQL injection vulnerabilities in the index.php page from POST parameters 'unametxt' and 'pwdtxt', which are not filtered before passing a SQL query. |