Vulnerabilities (CVE)

Filtered by vendor Kashipara Subscribe
Filtered by product Online Notice Board System
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-50760 1 Kashipara 1 Online Notice Board System 2024-11-21 N/A 8.8 HIGH
Online Notice Board System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'f' parameter of user/update_profile_pic.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
CVE-2023-50753 1 Kashipara 1 Online Notice Board System 2024-11-21 N/A 9.8 CRITICAL
Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the user/update_profile.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-50752 1 Kashipara 1 Online Notice Board System 2024-11-21 N/A 9.8 CRITICAL
Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'e' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-50743 1 Kashipara 1 Online Notice Board System 2024-11-21 N/A 9.8 CRITICAL
Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the registration.php resource does not validate the characters received and they are sent unfiltered to the database.