Aggregates CVE and security vulnerability intelligence across all dino_physics_school_assistant_project-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Common weakness patterns include vendor risk sql injection and vendor risk cross-site scripting, with potential vendor impact data exposure across vendor surface production workloads use cases.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2024-35359 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=view_item. Manipulating the argument id can result in SQL injection. | [email protected] | 9.8 | 0.16% | 2024-05-30 | 2024-11-21 |
| CVE-2024-35353 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Users.php?f=save. Manipulating the argument id can result in improper authorization. | [email protected] | 9.8 | 0.38% | 2024-05-30 | 2025-04-11 |
| CVE-2024-35352 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/Users.php?f=save. Manipulating the parameter middlename results in cross-site scripting. | [email protected] | 6.1 | 0.40% | 2024-05-30 | 2025-04-11 |
| CVE-2024-35351 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/SystemSettings.php?f=update_settings. Manipulating the parameter name results in cross-site scripting. | [email protected] | 5.4 | 0.24% | 2024-05-30 | 2025-04-11 |
| CVE-2024-35350 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/?page=borrow/view_borrow. Manipulating the argument id can result in SQL injection. | [email protected] | 9.8 | 0.19% | 2024-05-30 | 2025-04-11 |
| CVE-2024-35349 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/category/view_category.php. Manipulating the argument id can result in SQL injection. | [email protected] | 9.8 | 0.51% | 2024-05-30 | 2024-11-21 |
| CVE-2024-35358 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=view_category. Manipulating the argument id can result in SQL injection. | [email protected] | 6.5 | 0.12% | 2024-05-30 | 2025-04-11 |
| CVE-2024-35357 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=delete_item. Manipulating the argument id can result in SQL injection. | [email protected] | 5.3 | 0.15% | 2024-05-30 | 2025-04-11 |
| CVE-2024-35356 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=save_item. Manipulating the argument id can result in SQL injection. | [email protected] | 6.3 | 0.10% | 2024-05-30 | 2025-04-11 |
| CVE-2024-35355 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=delete_category. Manipulating the argument id can result in SQL injection. | [email protected] | 9.8 | 0.29% | 2024-05-30 | 2025-04-11 |
| CVE-2024-35354 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=save_category. Manipulating the argument id can result in SQL injection. | [email protected] | 9.8 | 0.29% | 2024-05-30 | 2025-04-11 |
| CVE-2024-35345 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts unidentified code within the file /classes/Users.php. Manipulating the argument id results in cross-site scripting. | [email protected] | 5.4 | 0.29% | 2024-05-30 | 2025-04-11 |