Casap Automated Enrollment System Project Casap Automated Enrollment System vulnerabilities
11 known vulnerabilities affecting casap_automated_enrollment_system_project/casap_automated_enrollment_system.
Total CVEs
11
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL5MEDIUM6
Vulnerabilities
Page 1 of 1
CVE-2021-3294P4MEDIUMCVSS 5.4PoCv1.02021-02-09
CVE-2021-3294 [MEDIUM] CWE-79 CVE-2021-3294: CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An att
CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a cookie to perform user redirection to a malicious website.
nvd
CVE-2021-26201P3CRITICALCVSS 9.8v1.02021-02-15
CVE-2021-26201 [CRITICAL] CWE-89 CVE-2021-26201: The Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authenticati
The Login Panel of CASAP Automated Enrollment System 1.0 is vulnerable to SQL injection authentication bypass. An attacker can obtain access to the admin panel by injecting a SQL query in the username field of the login page.
nvd
CVE-2021-26228P3CRITICALCVSS 9.8v1.02021-07-22
CVE-2021-26228 [CRITICAL] CWE-89 CVE-2021-26228: SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_class1.php.
nvd
CVE-2021-26229P3CRITICALCVSS 9.8v1.02021-07-22
CVE-2021-26229 [CRITICAL] CWE-89 CVE-2021-26229: SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_stud.php.
nvd
CVE-2021-26223P3CRITICALCVSS 9.8v1.02021-07-22
CVE-2021-26223 [CRITICAL] CWE-89 CVE-2021-26223: SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to view_pay.php.
nvd
CVE-2021-26226P3CRITICALCVSS 9.8v1.02021-07-22
CVE-2021-26226 [CRITICAL] CWE-89 CVE-2021-26226: SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote
SQL injection vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit_user.php.
nvd
CVE-2021-40261P4MEDIUMCVSS 6.1v1.02021-11-08
CVE-2021-40261 [MEDIUM] CWE-79 CVE-2021-40261: Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester CASAP Automated Enrollme
Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester CASAP Automated Enrollment System 1.0 via the (1) user_username and (2) category parameters in save_class.php, the (3) firstname, (4) class, and (5) status parameters in student_table.php, the (6) category and (7) class_name parameters in add_class1.php, the (8) fname, (9) mn
nvd
CVE-2021-26230P4MEDIUMCVSS 6.1v1.02021-07-22
CVE-2021-26230 [MEDIUM] CWE-79 CVE-2021-26230: Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 a
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the user information to save_user.php.
nvd
CVE-2021-26227P4MEDIUMCVSS 6.1v1.02021-07-22
CVE-2021-26227 [MEDIUM] CWE-79 CVE-2021-26227: Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 a
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the student information parameters to edit_stud.php.
nvd
CVE-2021-27332P4MEDIUMCVSS 6.1v1.02021-07-22
CVE-2021-27332 [MEDIUM] CWE-79 CVE-2021-27332: Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 a
Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the class_name parameter to update_class.php.
nvd
CVE-2021-27129P4MEDIUMCVSS 5.4v1.02021-04-15
CVE-2021-27129 [MEDIUM] CWE-79 CVE-2021-27129: CASAP Automated Enrollment System version 1.0 contains a cross-site scripting (XSS) vulnerability th
CASAP Automated Enrollment System version 1.0 contains a cross-site scripting (XSS) vulnerability through the Students > Edit > ROUTE parameter.
nvd