This page lists publicly disclosed CVE vulnerabilities affecting lopalopa responsive_school_management_system (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2024-41236 | A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter of the Admin Login Page | [email protected] | 7.2 | 0.38% | 2024-08-28 | 2024-08-30 |
| CVE-2024-41238 | A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter. | [email protected] | 5.3 | 0.38% | 2024-08-08 | 2024-08-12 |
| CVE-2024-41239 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/smsa/add_class_submit.php" in Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "class_name" parameter field. | [email protected] | 4.8 | 0.48% | 2024-08-07 | 2024-08-08 |
| CVE-2024-41237 | A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter. | [email protected] | 9.8 | 0.59% | 2024-08-07 | 2024-08-08 |
| CVE-2024-41242 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /smsa/student_login.php in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "error" parameter. | [email protected] | 6.1 | 0.45% | 2024-08-07 | 2024-08-08 |
| CVE-2024-41241 | A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/admin_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via "error" parameter. | [email protected] | 6.1 | 0.43% | 2024-08-07 | 2024-09-03 |
| CVE-2024-41240 | A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/teacher_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via the "error" parameter. | [email protected] | 6.1 | 0.45% | 2024-08-07 | 2024-08-13 |
| CVE-2024-41250 | An Incorrect Access Control vulnerability was found in /smsa/view_students.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view STUDENT details. | [email protected] | 5.3 | 0.48% | 2024-08-07 | 2025-03-14 |
| CVE-2024-41245 | An Incorrect Access Control vulnerability was found in /smsa/view_teachers.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view TEACHER details. | [email protected] | 5.3 | 0.55% | 2024-08-07 | 2024-08-08 |
| CVE-2024-41244 | An Incorrect Access Control vulnerability was found in /smsa/view_class.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view CLASS details. | [email protected] | 5.3 | 0.47% | 2024-08-07 | 2024-08-08 |
| CVE-2024-41243 | An Incorrect Access Control vulnerability was found in /smsa/view_marks.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view MARKS details. | [email protected] | 5.3 | 0.51% | 2024-08-07 | 2025-03-19 |
| CVE-2024-41252 | An Incorrect Access Control vulnerability was found in /smsa/admin_student_register_approval.php and /smsa/admin_student_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve student registration. | [email protected] | 6.5 | 0.39% | 2024-08-07 | 2024-08-08 |
| CVE-2024-41251 | An Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve Teacher registration. | [email protected] | 6.5 | 0.45% | 2024-08-07 | 2025-03-13 |
| CVE-2024-41249 | An Incorrect Access Control vulnerability was found in /smsa/view_subject.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view SUBJECT details. | [email protected] | 5.3 | 0.64% | 2024-08-07 | 2024-08-08 |
| CVE-2024-41248 | An Incorrect Access Control vulnerability was found in /smsa/add_subject.php and /smsa/add_subject_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new subject entry. | [email protected] | 5.3 | 0.54% | 2024-08-07 | 2024-08-08 |
| CVE-2024-41247 | An Incorrect Access Control vulnerability was found in /smsa/add_class.php and /smsa/add_class_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add a new class entry. | [email protected] | 5.3 | 0.43% | 2024-08-07 | 2024-08-08 |
| CVE-2024-41246 | An Incorrect Access Control vulnerability was found in /smsa/admin_dashboard.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view administrator dashboard. | [email protected] | 5.3 | 0.54% | 2024-08-07 | 2025-03-27 |