Stock Management System Project
Stock Management System Project Stock Management System: vulnerabilidades y CVE
Stock Management System Project Stock Management System tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-36779 | Crítica (9.8) | 0.57% | — | 6 jun 2024 | Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php. |
| CVE-2023-51951 | Crítica (9.8) | 1.4% | — | 5 feb 2024 | SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id parameter in the manage_bo.php file. |
| CVE-2022-4090 | Alta (8.8) | 0.26% | — | 24 nov 2022 | A vulnerability was found in rickxy Stock Management System and classified as problematic. This issue affects some unknown processing of the file us_transac.php?action=add. The manipulation leads to cross-site request… |
| CVE-2022-4089 | Media (5.4) | 0.40% | — | 24 nov 2022 | A vulnerability was found in rickxy Stock Management System. It has been declared as problematic. This vulnerability affects unknown code of the file /pages/processlogin.php. The manipulation of the argument user leads… |
| CVE-2022-4088 | Crítica (9.8) | 0.60% | — | 24 nov 2022 | A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. The manipulation of the argument… |
| CVE-2021-44114 | Media (4.8) | 1.00% | — | 31 ene 2022 | Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Stock Management System in PHP/OOP 1.0, which allows remote malicious users to execute arbitrary remote code execution via create user function. |
| CVE-2020-24198 | Media (6.1) | 0.83% | — | 9 sept 2020 | A persistent cross-site scripting vulnerability in Sourcecodester Stock Management System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'Brand Name.' |
| CVE-2020-24197 | Crítica (9.8) | 1.4% | — | 9 sept 2020 | A SQL injection vulnerability in the login component in Stock Management System v1.0 allows remote attacker to execute arbitrary SQL commands via the username parameter. |
| CVE-2020-23830 | Alta (7.1) | 0.53% | — | 2 sept 2020 | A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 allows remote attackers to deny future logins by changing an authenticated victim's username when… |
| CVE-2020-23831 | Media (6.1) | 0.84% | — | 1 sept 2020 | A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Stock Management System v1.0 allows remote attackers to harvest login credentials and session cookies when an… |