alumni_management_system_project CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

alumni_management_system_project vulnerability overview

Aggregates CVE and security vulnerability intelligence across all alumni_management_system_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk sql injection and vendor risk cross-site scripting and related problems; some flaws may lead to vendor impact data exposure and vendor impact session compromise.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2021-25212 SQL injection vulnerability in SourceCodester Alumni Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to manage_event.php. [email protected] 9.8 1.48% 2021-07-22 2024-11-21
CVE-2021-25210 Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to manage_event.php. [email protected] 9.8 1.48% 2021-07-22 2024-11-21
CVE-2020-29214 SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admin/login.php. [email protected] 9.8 4.50% 2021-06-15 2024-11-21
CVE-2020-28071 SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' and reach a stored XSS. [email protected] 4.8 0.64% 2020-12-23 2024-11-21
CVE-2020-28070 SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via the 'id' parameter. [email protected] 9.8 22.90% 2020-12-23 2024-11-21
CVE-2020-28072 A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in the gallery.php page and executing it on the server reaching the RCE. [email protected] 7.2 2.63% 2020-12-15 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence