lopalopa e-learning_management_system CVE Vulnerabilities (41)

CVEs: 41 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting lopalopa e-learning_management_system (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 120 of 41 CVEs
«« First « Prev Page 1 / 3 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-54938 A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads. [email protected] 7.5 0.15% 2024-12-09 2025-04-24
CVE-2024-54934 Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php. [email protected] 9.8 0.16% 2024-12-09 2025-04-24
CVE-2024-54932 Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php. [email protected] 9.8 0.16% 2024-12-09 2025-04-24
CVE-2024-54931 A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter. [email protected] 9.8 1.05% 2024-12-09 2025-04-24
CVE-2024-54928 kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php, [email protected] 7.2 0.08% 2024-12-09 2025-04-24
CVE-2024-54927 Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php. [email protected] 7.2 0.08% 2024-12-09 2025-04-24
CVE-2024-54925 A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter. [email protected] 9.8 1.05% 2024-12-09 2025-04-14
CVE-2024-54924 A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the title and content parameters. [email protected] 9.8 1.05% 2024-12-09 2025-04-14
CVE-2024-54923 A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the department parameter. [email protected] 9.8 1.05% 2024-12-09 2025-04-14
CVE-2024-54921 A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username, firstname, lastname, and class_id parameters. [email protected] 9.8 0.54% 2024-12-09 2025-04-14
CVE-2024-54918 Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php. [email protected] 9.8 5.17% 2024-12-09 2025-04-14
CVE-2024-54935 A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter. [email protected] 5.4 0.33% 2024-12-09 2024-12-11
CVE-2024-54933 Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php. [email protected] 7.2 0.18% 2024-12-09 2024-12-12
CVE-2024-54930 Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php. [email protected] 7.2 0.12% 2024-12-09 2024-12-12
CVE-2024-54922 A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the firstname, lastname, and username parameters. [email protected] 7.2 0.98% 2024-12-09 2024-12-12
CVE-2024-54926 A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the school_year parameter. [email protected] 8.8 1.48% 2024-12-09 2024-12-11
CVE-2024-54920 A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the firstname, lastname, and class_id parameters. [email protected] 9.8 2.00% 2024-12-09 2025-03-20
CVE-2024-54919 A Stored Cross Site Scripting (XSS ) was found in /teacher_avatar.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary java script via the filename parameter. [email protected] 5.4 0.19% 2024-12-09 2024-12-10
CVE-2024-54937 A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/assets. [email protected] 5.3 0.39% 2024-12-09 2025-03-20
CVE-2024-54936 A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message.php of Kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the my_message parameter. [email protected] 5.4 0.36% 2024-12-09 2024-12-10
«« First « Prev Page 1 / 3 Next »
cvelogic Threat Intelligence