Wedding Management System Project
Wedding Management System Project Wedding Management System: vulnerabilidades y CVE
Wedding Management System Project Wedding Management System tiene 20 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-30836 | Alta (7.2) | 0.99% | — | 2 jun 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection. via Wedding-Management/admin/select.php. |
| CVE-2022-30835 | Alta (7.2) | 0.99% | — | 2 jun 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection. via /Wedding-Management/admin/budget.php?booking_id=. |
| CVE-2022-30834 | Alta (7.2) | 1.0% | — | 2 jun 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_manage_account_details.php?booking_id=31&user_id= |
| CVE-2022-30833 | Alta (7.2) | 1.0% | — | 2 jun 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_edit.php?booking=31&user_id=. |
| CVE-2022-30832 | Alta (7.2) | 0.99% | — | 2 jun 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_assign.php?booking=31&user_id=. |
| CVE-2022-30831 | Alta (7.2) | 1.0% | — | 2 jun 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via Wedding-Management/wedding_details.php. |
| CVE-2022-30830 | Alta (7.2) | 1.0% | — | 2 jun 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\feature_edit.php. |
| CVE-2022-30829 | Alta (7.2) | 0.99% | — | 2 jun 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\users_edit.php. |
| CVE-2022-30828 | Alta (7.2) | 1.0% | — | 2 jun 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\photos_edit.php. |
| CVE-2022-30827 | Alta (7.2) | 1.0% | — | 2 jun 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\package_edit.php. |
| CVE-2022-30826 | Alta (7.2) | 1.0% | — | 2 jun 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via admin\client_assign.php. |
| CVE-2022-30825 | Alta (7.2) | 1.0% | — | 2 jun 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\client_edit.php. |
| CVE-2022-30823 | Alta (7.2) | 1.0% | — | 2 jun 2022 | Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\blog_events_edit.php. |
| CVE-2022-30822 | Alta (8.8) | 1.2% | — | 2 jun 2022 | In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_profile.php" file. |
| CVE-2022-30821 | Alta (8.8) | 1.2% | — | 2 jun 2022 | In Wedding Management System v1.0, the editing function of the "Services" module in the background management system has an arbitrary file upload vulnerability in the picture upload point of "package_edit.php" file. |
| CVE-2022-30820 | Alta (8.8) | 1.2% | — | 2 jun 2022 | In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.php" file. |
| CVE-2022-30819 | Alta (8.8) | 1.2% | — | 2 jun 2022 | In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "photos_edit.php" file. |
| CVE-2022-30818 | Alta (7.2) | 1.0% | — | 2 jun 2022 | Wedding Management System v1.0 is vulnerable to SQL injection via /Wedding-Management/admin/blog_events_edit.php?id=31. |
| CVE-2022-29656 | Crítica (9.8) | 0.94% | — | 11 may 2022 | Wedding Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Wedding-Management/package_detail.php. |
| CVE-2022-29655 | Alta (7.2) | 1.5% | — | 11 may 2022 | An arbitrary file upload vulnerability in the Upload Photos module of Wedding Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. |