Home Owners Collection Management System Project
Home Owners Collection Management System Project Home Owners Collection Management System: vulnerabilidades y CVE
Home Owners Collection Management System Project Home Owners Collection Management System tiene 15 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses0
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-6440 | Media (5.3) | 0.53% | — | 2 jul 2024 | A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /classes/Master.php?f=delete_category. The… |
| CVE-2024-6439 | Media (5.3) | 0.68% | — | 2 jul 2024 | A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Users.php?f=save. The manipulation of… |
| CVE-2022-28078 | Media (6.1) | 1.1% | — | 11 may 2022 | Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['page'] parameter. |
| CVE-2022-28077 | Media (6.1) | 0.83% | — | 11 may 2022 | Home Owners Collection Management v1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the Admin panel via the $_GET['s'] parameter. |
| CVE-2022-28417 | Crítica (9.8) | 1.3% | — | 21 abr 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase. |
| CVE-2022-28416 | Crítica (9.8) | 1.3% | — | 21 abr 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase. |
| CVE-2022-28415 | Crítica (9.8) | 1.3% | — | 21 abr 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_collection. |
| CVE-2022-28414 | Crítica (9.8) | 1.2% | — | 21 abr 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_member. |
| CVE-2022-25115 | Alta (7.8) | 1.6% | — | 2 mar 2022 | A remote code execution (RCE) vulnerability in the Avatar parameter under /admin/?page=user/manage_user of Home Owners Collection Management System v1.0 allows attackers to execute arbitrary code via a crafted PNG file. |
| CVE-2022-25045 | Crítica (9.8) | 1.3% | — | 2 mar 2022 | Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel. |
| CVE-2022-25016 | Crítica (9.8) | 2.0% | — | 2 mar 2022 | Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/index.php. This vulnerability allows attackers to execute arbitrary… |
| CVE-2022-25028 | Media (6.1) | 0.64% | — | 28 feb 2022 | Home Owners Collection Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the collected_by parameter under the List of Collections module. |
| CVE-2022-25096 | Crítica (9.8) | 2.1% | — | 26 feb 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php. |
| CVE-2022-25095 | Crítica (9.8) | 1.4% | — | 26 feb 2022 | Home Owners Collection Management System v1.0 allows unauthenticated attackers to compromise user accounts via a crafted POST request. |
| CVE-2022-25094 | Alta (8.8) | 23% | — | 26 feb 2022 | Home Owners Collection Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the parameter "cover" in SystemSettings.php. |