Vulnerabilities (CVE)

Filtered by CWE-89
Total 14188 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-31908 1 Student Registration And Fee Payment System Project 1 Student Registration And Fee Payment System 2022-06-27 6.5 MEDIUM 7.2 HIGH
Student Registration and Fee Payment System v1.0 is vulnerable to SQL Injection via /scms/student.php.
CVE-2022-31912 1 Online Tutor Portal Site Project 1 Online Tutor Portal Site 2022-06-27 6.5 MEDIUM 7.2 HIGH
Online Tutor Portal Site v1.0 is vulnerable to SQL Injection via /otps/classes/Master.php?f=delete_team.
CVE-2022-32370 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_classroom.php?id=.
CVE-2022-32371 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_teacher.php?id=.
CVE-2022-32372 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_subject.php?id=.
CVE-2022-32374 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_subject_routing.php?id=.
CVE-2022-32373 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_exam.php?id=.
CVE-2022-32368 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_grade.php?id=.
CVE-2022-32101 1 Kkcms Project 1 Kkcms 2022-06-24 7.5 HIGH 9.8 CRITICAL
kkcms v1.3.7 was discovered to contain a SQL injection vulnerability via the cid parameter at /template/wapian/vlist.php.
CVE-2022-32302 1 Theme Park Ticketing System Project 1 Theme Park Ticketing System 2022-06-24 6.5 MEDIUM 8.8 HIGH
Theme Park Ticketing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edit_ticket.php.
CVE-2022-32991 1 Web Based Quiz System Project 1 Web Based Quiz System 2022-06-24 6.5 MEDIUM 8.8 HIGH
Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the eid parameter at welcome.php.
CVE-2022-32992 1 Online Tours And Travels Management System Project 1 Online Tours And Travels Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the tname parameter at /admin/operations/tax.php.
CVE-2022-32375 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_timetable.php?id=.
CVE-2022-32376 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_events.php?event_id=.
CVE-2022-32378 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_teacher_profile.php?my_index=.
CVE-2022-32377 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_exam_timetable.php?id=.
CVE-2022-32379 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_parents_profile.php?my_index=.
CVE-2022-32380 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_student_subject.php?index=.
CVE-2022-32381 1 Advanced School Management System Project 1 Advanced School Management System 2022-06-24 6.5 MEDIUM 7.2 HIGH
itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_admin_profile.php?my_index=.
CVE-2022-2086 1 Bank Management System Project 1 Bank Management System 2022-06-23 6.5 MEDIUM 8.8 HIGH
A vulnerability, which was classified as critical, has been found in SourceCodester Bank Management System 1.0. Affected by this issue is login.php. The manipulation of the argument password with the input 1'and 1=2 union select 1,sleep(10),3,4,5 --+ leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.