Lopalopa
Lopalopa E-learning Management System: vulnerabilities and CVEs
Lopalopa E-learning Management System has 41 published vulnerabilities, 0 of them in the last 12 months. 11 are rated critical and 0 are listed by CISA as actively exploited.
CVEs41
Last 12 months0
Critical11
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54938 | High (7.5) | 0.56% | — | Dec 9, 2024 | A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads. |
| CVE-2024-54934 | Critical (9.8) | 0.51% | — | Dec 9, 2024 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php. |
| CVE-2024-54932 | Critical (9.8) | 0.51% | — | Dec 9, 2024 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php. |
| CVE-2024-54931 | Critical (9.8) | 0.60% | — | Dec 9, 2024 | A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id… |
| CVE-2024-54928 | High (7.2) | 0.49% | — | Dec 9, 2024 | kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php, |
| CVE-2024-54927 | High (7.2) | 0.49% | — | Dec 9, 2024 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php. |
| CVE-2024-54925 | Critical (9.8) | 0.60% | — | Dec 9, 2024 | A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id… |
| CVE-2024-54924 | Critical (9.8) | 0.60% | — | Dec 9, 2024 | A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the title and… |
| CVE-2024-54923 | Critical (9.8) | 0.60% | — | Dec 9, 2024 | A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via… |
| CVE-2024-54921 | Critical (9.8) | 0.60% | — | Dec 9, 2024 | A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username,… |
| CVE-2024-54918 | Critical (9.8) | 0.92% | — | Dec 9, 2024 | Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php. |
| CVE-2024-54935 | Medium (5.4) | 0.39% | — | Dec 9, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts… |
| CVE-2024-54933 | High (7.2) | 0.49% | — | Dec 9, 2024 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php. |
| CVE-2024-54930 | High (7.2) | 0.49% | — | Dec 9, 2024 | Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php. |
| CVE-2024-54922 | High (7.2) | 0.58% | — | Dec 9, 2024 | A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname,… |
| CVE-2024-54926 | High (8.8) | 0.58% | — | Dec 9, 2024 | A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the… |
| CVE-2024-54920 | Critical (9.8) | 0.60% | — | Dec 9, 2024 | A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the… |
| CVE-2024-54919 | Medium (5.4) | 0.32% | — | Dec 9, 2024 | A Stored Cross Site Scripting (XSS ) was found in /teacher_avatar.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary java script via the filename… |
| CVE-2024-54937 | Medium (5.3) | 0.47% | — | Dec 9, 2024 | A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/assets. |
| CVE-2024-54936 | Medium (5.4) | 0.41% | — | Dec 9, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message.php of Kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message… |
| CVE-2024-54929 | High (7.2) | 0.51% | — | Dec 9, 2024 | KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php. |
| CVE-2024-50831 | High (7.2) | 0.38% | — | Nov 14, 2024 | A SQL Injection was found in /admin/admin_user.php in kashipara E-learning Management System Project 1.0 via the username and password parameters. |
| CVE-2024-50830 | High (7.2) | 0.38% | — | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/calendar_of_events.php in kashipara E-learning Management System Project 1.0 via the date_start, date_end, and title parameters. |
| CVE-2024-50829 | High (7.2) | 0.38% | — | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0 via the unit parameter. |
| CVE-2024-50828 | High (7.2) | 0.38% | — | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/edit_department.php in kashipara E-learning Management System Project 1.0 via the d parameter. |
| CVE-2024-50827 | High (7.2) | 0.38% | — | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 via the subject_code parameter. |
| CVE-2024-50826 | High (7.2) | 0.38% | — | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 via the title and content parameters. |
| CVE-2024-50825 | High (7.2) | 0.38% | — | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 via the school_year parameter. |
| CVE-2024-50824 | High (7.2) | 0.47% | — | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter. |
| CVE-2024-50823 | Critical (9.8) | 0.49% | — | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and password parameters. |