Vulnerabilities (CVE)

Filtered by vendor Angeljudesuarez Subscribe
Total 53 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-6042 1 Angeljudesuarez 1 Real Estate Management System 2024-11-21 7.5 HIGH 7.3 HIGH
A vulnerability was found in itsourcecode Real Estate Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file property-detail.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-268766 is the identifier assigned to this vulnerability.
CVE-2024-5981 1 Angeljudesuarez 1 Online House Rental System 2024-11-21 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in itsourcecode Online House Rental System 1.0. It has been classified as critical. Affected is an unknown function of the file manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-268458 is the identifier assigned to this vulnerability.
CVE-2024-5898 1 Angeljudesuarez 1 Payroll Management System 2024-11-21 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in itsourcecode Payroll Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file print_payroll.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-268142 is the identifier assigned to this vulnerability.
CVE-2024-40393 1 Angeljudesuarez 1 Online Clinic Management System 2024-11-21 N/A 9.8 CRITICAL
Online Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerability via the user parameter at login.php.
CVE-2024-50972 1 Angeljudesuarez 1 Construction Management System 2024-11-18 N/A 7.2 HIGH
A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.
CVE-2024-50971 1 Angeljudesuarez 1 Construction Management System 2024-11-18 N/A 7.2 HIGH
A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the map_id parameter.
CVE-2024-11074 1 Angeljudesuarez 1 Tailoring Management System 2024-11-14 6.5 MEDIUM 9.8 CRITICAL
A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. This vulnerability affects unknown code of the file /incadd.php. The manipulation of the argument inccat/desc/date/amount leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "inccat" to be affected. But it must be assumed "desc", "date", and "amount" are affected as well.
CVE-2024-10738 1 Angeljudesuarez 1 Farm Management System 2024-11-05 6.5 MEDIUM 9.8 CRITICAL
A vulnerability classified as critical was found in itsourcecode Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file manage-breed.php. The manipulation of the argument breed leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-10759 1 Angeljudesuarez 1 Farm Management System 2024-11-05 6.5 MEDIUM 8.8 HIGH
A vulnerability has been found in itsourcecode Farm Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /edit-pig.php. The manipulation of the argument pigno/weight/arrived/breed/remark/status leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "pigno" to be affected. But it must be assumed that other parameters are affected as well.
CVE-2024-10609 1 Angeljudesuarez 1 Tailoring Management System 2024-11-05 6.5 MEDIUM 9.8 CRITICAL
A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System Project 1.0. This affects an unknown part of the file typeadd.php. The manipulation of the argument sex leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-48656 1 Angeljudesuarez 1 Student Management System 2024-10-24 N/A 4.8 MEDIUM
Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code.
CVE-2024-46300 1 Angeljudesuarez 1 Placement Management System 2024-10-10 N/A 6.1 MEDIUM
itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.
CVE-2024-8611 1 Angeljudesuarez 1 Tailoring Management System 2024-09-18 6.5 MEDIUM 9.8 CRITICAL
A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file ssms.php. The manipulation of the argument customer leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-7500 1 Angeljudesuarez 1 Airline Reservation System 2024-09-11 6.5 MEDIUM 9.8 CRITICAL
A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been rated as critical. Affected by this issue is the function save_settings of the file admin/admin_class.php. The manipulation of the argument img leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-273626 is the identifier assigned to this vulnerability.
CVE-2024-7506 1 Angeljudesuarez 1 Tailoring Management System 2024-09-11 6.5 MEDIUM 8.8 HIGH
A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /setlogo.php. The manipulation of the argument bgimg leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273649 was assigned to this vulnerability.
CVE-2024-8570 1 Angeljudesuarez 1 Tailoring Management System 2024-09-11 6.5 MEDIUM 9.8 CRITICAL
A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /inccatadd.php. The manipulation of the argument title leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-44728 1 Angeljudesuarez 1 Event Management System 2024-09-06 N/A 6.1 MEDIUM
Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, and contact# in /clientdetails/admin/regester.php.
CVE-2024-44727 1 Angeljudesuarez 1 Event Management System 2024-09-06 N/A 9.8 CRITICAL
Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php.
CVE-2024-8139 1 Angeljudesuarez 1 E-commerce Website 2024-09-04 6.5 MEDIUM 9.8 CRITICAL
A vulnerability has been found in itsourcecode E-Commerce Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file search_list.php. The manipulation of the argument user leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-8220 1 Angeljudesuarez 1 Tailoring Management System 2024-08-29 6.5 MEDIUM 9.8 CRITICAL
A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file staffedit.php. The manipulation of the argument id/stafftype/address/fullname/phonenumber/salary leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.