本ページは oretnom23 cab_management_system に影響する公開済み CVE(NVD の CPE 経由で関連付け)を列挙します。各行に深刻度指標・概要・公開日が含まれます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2026-36923 | Sourcecodester Cab Management System 1.0 is vulnerable to SQL Injection in the file /cms/admin/bookings/view_booking.php. | [email protected] | 2.7 | 0.22% | 2026-04-13 | 2026-06-17 |
| CVE-2026-36922 | Sourcecodester Cab Management System v1.0 is vulnerable to SQL injection in the file /cms/admin/categories/view_category.php. | [email protected] | 2.7 | 0.22% | 2026-04-13 | 2026-06-17 |
| CVE-2024-51031 | A Cross-site Scripting (XSS) vulnerability in manage_account.php in Sourcecodester Cab Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "First Name," "Middle Name," and "Last Name" fields. | [email protected] | 5.4 | 0.40% | 2024-11-08 | 2026-06-17 |
| CVE-2024-51030 | A SQL injection vulnerability in manage_client.php and view_cab.php of Sourcecodester Cab Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, leading to unauthorized access and potential compromise of sensitive data within the database. | [email protected] | 6.5 | 0.68% | 2024-11-08 | 2026-06-17 |
| CVE-2024-5893 | A vulnerability classified as critical has been found in SourceCodester Cab Management System 1.0. This affects an unknown part of the file /cms/classes/Users.php?f=delete_client. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-268137 was assigned to this vulnerability. | [email protected] | 5.3 | 0.54% | 2024-06-12 | 2026-06-17 |