Alumni Management System Project Alumni Management System vulnerabilities
6 known vulnerabilities affecting alumni_management_system_project/alumni_management_system.
Total CVEs
6
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-29214P2CRITICALCVSS 9.8PoCv1.02021-06-15
CVE-2020-29214 [CRITICAL] CWE-89 CVE-2020-29214: SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject
SQL injection vulnerability in SourceCodester Alumni Management System 1.0 allows the user to inject SQL payload to bypass the authentication via admin/login.php.
nvd
CVE-2020-28070P2CRITICALCVSS 9.8v1.02020-12-23
CVE-2020-28070 [CRITICAL] CWE-89 CVE-2020-28070: SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote co
SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via the 'id' parameter.
nvd
CVE-2021-25210P3CRITICALCVSS 9.8v1.02021-07-22
CVE-2021-25210 [CRITICAL] CWE-434 CVE-2021-25210: Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attacker
Arbitrary file upload vulnerability in SourceCodester Alumni Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to manage_event.php.
nvd
CVE-2021-25212P3CRITICALCVSS 9.8v1.02021-07-22
CVE-2021-25212 [CRITICAL] CWE-89 CVE-2021-25212: SQL injection vulnerability in SourceCodester Alumni Management System v 1.0 allows remote attackers
SQL injection vulnerability in SourceCodester Alumni Management System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to manage_event.php.
nvd
CVE-2020-28072P3HIGHCVSS 7.2v1.02020-12-15
CVE-2020-28072 [HIGH] CWE-434 CVE-2020-28072: A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An auth
A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in the gallery.php page and executing it on the server reaching the RCE.
nvd
CVE-2020-28071P4MEDIUMCVSS 4.8v1.02020-12-23
CVE-2020-28071 [MEDIUM] CWE-79 CVE-2020-28071: SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gall
SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'about' and reach a stored XSS.
nvd