Kashipara
Kashipara Billing Software: vulnerabilidades y CVE
Kashipara Billing Software tiene 14 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 14 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses0
Críticas14
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-49641 | Crítica (9.8) | 0.40% | — | 13 may 2025 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginCheck.php resource does not validate the characters received and they are sent… |
| CVE-2024-0496 | Crítica (9.8) | 0.64% | — | 13 ene 2024 | A vulnerability was found in Kashipara Billing Software 1.0 and classified as critical. This issue affects some unknown processing of the file item_list_edit.php of the component HTTP POST Request Handler. The… |
| CVE-2024-0495 | Crítica (9.8) | 0.57% | — | 13 ene 2024 | A vulnerability has been found in Kashipara Billing Software 1.0 and classified as critical. This vulnerability affects unknown code of the file party_submit.php of the component HTTP POST Request Handler. The… |
| CVE-2024-0494 | Crítica (9.8) | 0.53% | — | 13 ene 2024 | A vulnerability, which was classified as critical, was found in Kashipara Billing Software 1.0. This affects an unknown part of the file material_bill.php of the component HTTP POST Request Handler. The manipulation of… |
| CVE-2024-0493 | Crítica (9.8) | 0.53% | — | 13 ene 2024 | A vulnerability, which was classified as critical, has been found in Kashipara Billing Software 1.0. Affected by this issue is some unknown functionality of the file submit_delivery_list.php of the component HTTP POST… |
| CVE-2024-0492 | Crítica (9.8) | 0.53% | — | 13 ene 2024 | A vulnerability classified as critical was found in Kashipara Billing Software 1.0. Affected by this vulnerability is an unknown functionality of the file buyer_detail_submit.php of the component HTTP POST Request… |
| CVE-2023-49666 | Crítica (9.8) | 0.75% | — | 4 ene 2024 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'custmer_details' parameter of the submit_material_list.php resource does not validate the characters received and they… |
| CVE-2023-49665 | Crítica (9.8) | 0.67% | — | 4 ene 2024 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'quantity[]' parameter of the submit_delivery_list.php resource does not validate the characters received and they are… |
| CVE-2023-49658 | Crítica (9.8) | 0.67% | — | 4 ene 2024 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'bank_details' parameter of the party_submit.php resource does not validate the characters received and they are sent… |
| CVE-2023-49639 | Crítica (9.8) | 0.67% | — | 4 ene 2024 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'customer_details' parameter of the buyer_invoice_submit.php resource does not validate the characters received and they… |
| CVE-2023-49633 | Crítica (9.8) | 0.67% | — | 4 ene 2024 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'buyer_address' parameter of the buyer_detail_submit.php resource does not validate the characters received and they are… |
| CVE-2023-49625 | Crítica (9.8) | 0.67% | — | 4 ene 2024 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partylist_edit_submit.php resource does not validate the characters received and they are sent… |
| CVE-2023-49624 | Crítica (9.8) | 0.67% | — | 4 ene 2024 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cancelid' parameter of the material_bill.php resource does not validate the characters received and they are sent… |
| CVE-2023-49622 | Crítica (9.8) | 0.67% | — | 4 ene 2024 | Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'itemnameid' parameter of the material_bill.php?action=itemRelation resource does not validate the characters received… |