Phpgurukul
Phpgurukul Client Management System: vulnerabilidades y CVE
Phpgurukul Client Management System tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-51209 | Media (5.4) | 0.27% | — | 20 nov 2024 | Cross-Site Scripting (XSS) vulnerabilities in Anuj Kumar's Client Management System Version 1.2 allow local attackers to inject arbitrary web script or HTML via the search input field parameter to admin search invoice… |
| CVE-2024-48570 | Alta (7.5) | 0.51% | — | 22 oct 2024 | Client Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports parameter at /admin/bwdates-reports-ds.php. |
| CVE-2024-30990 | Crítica (9.8) | 0.63% | — | 17 abr 2024 | SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "searchdata" parameter. |
| CVE-2024-30989 | Media (5.4) | 0.44% | — | 17 abr 2024 | Cross Site Scripting vulnerability in /edit-client-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code via the "cname", "comname", "state" and "city"… |
| CVE-2024-30988 | Media (6.8) | 0.58% | — | 17 abr 2024 | Cross Site Scripting vulnerability in /search-invoices.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the Search bar. |
| CVE-2024-30987 | Media (6.8) | 0.58% | — | 17 abr 2024 | Cross Site Scripting vulnerability in /bwdates-reports-ds.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the fromdate and… |
| CVE-2024-30986 | Media (6.5) | 0.43% | — | 17 abr 2024 | Cross Site Scripting vulnerability in /edit-services-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and via "price" and "sname" parameter. |
| CVE-2024-30985 | Crítica (9.8) | 0.69% | — | 17 abr 2024 | SQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "todate" and "fromdate" parameters. |
Otros productos de Phpgurukul
Hospital Management System · 62Online Shopping Portal · 43ZOO Management System · 37ART Gallery Management System · 36Online Fire Reporting System · 32Complaint Management System · 32Student Record System · 29Beauty Parlour Management System · 28User Registration & Login AND User Management System · 25Land Record System · 25Pre-school Enrollment System · 25Dairy Farm Shop Management System · 24