Code-Projects Simple Admin Panel vulnerabilities
14 known vulnerabilities affecting code-projects/simple_admin_panel.
Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM13
Vulnerabilities
Page 1 of 1
CVE-2024-12933MEDIUMCVSS 5.3v1.02024-12-26
CVE-2024-12933 [MEDIUM] CWE-79 CVE-2024-12933: A vulnerability was found in code-projects Simple Admin Panel 1.0. It has been rated as problematic.
A vulnerability was found in code-projects Simple Admin Panel 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file updateItemController.php. The manipulation of the argument p_name/p_desc leads to cross site scripting. The attack may be launched remotely.
cvelistv5nvd
CVE-2024-12936MEDIUMCVSS 5.3v1.02024-12-26
CVE-2024-12936 [MEDIUM] CWE-74 CVE-2024-12936: A vulnerability, which was classified as critical, has been found in code-projects Simple Admin Pane
A vulnerability, which was classified as critical, has been found in code-projects Simple Admin Panel 1.0. This issue affects some unknown processing of the file catDeleteController.php. The manipulation of the argument record leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2024-12935MEDIUMCVSS 5.3v1.02024-12-26
CVE-2024-12935 [MEDIUM] CWE-74 CVE-2024-12935: A vulnerability classified as critical was found in code-projects Simple Admin Panel 1.0. This vulne
A vulnerability classified as critical was found in code-projects Simple Admin Panel 1.0. This vulnerability affects unknown code of the file editItemForm.php. The manipulation of the argument record leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2024-12928MEDIUMCVSS 5.3v1.02024-12-26
CVE-2024-12928 [MEDIUM] CWE-74 CVE-2024-12928: A vulnerability, which was classified as critical, was found in code-projects Simple Admin Panel 1.0
A vulnerability, which was classified as critical, was found in code-projects Simple Admin Panel 1.0. This affects an unknown part. The manipulation of the argument c_name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2024-12937MEDIUMCVSS 5.3v1.02024-12-26
CVE-2024-12937 [MEDIUM] CWE-74 CVE-2024-12937: A vulnerability, which was classified as critical, was found in code-projects Simple Admin Panel 1.0
A vulnerability, which was classified as critical, was found in code-projects Simple Admin Panel 1.0. Affected is an unknown function of the file addVariationController.php. The manipulation of the argument qty leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2024-12931MEDIUMCVSS 5.3v1.02024-12-26
CVE-2024-12931 [MEDIUM] CWE-74 CVE-2024-12931: A vulnerability was found in code-projects Simple Admin Panel 1.0. It has been classified as critica
A vulnerability was found in code-projects Simple Admin Panel 1.0. It has been classified as critical. Affected is an unknown function of the file /addCatController.php. The manipulation of the argument size leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2024-12930MEDIUMCVSS 5.3v1.02024-12-26
CVE-2024-12930 [MEDIUM] CWE-79 CVE-2024-12930: A vulnerability was found in code-projects Simple Admin Panel 1.0 and classified as problematic. Thi
A vulnerability was found in code-projects Simple Admin Panel 1.0 and classified as problematic. This issue affects some unknown processing of the file addCatController.php. The manipulation of the argument c_name leads to cross site scripting. The attack may be initiated remotely.
cvelistv5nvd
CVE-2024-12932MEDIUMCVSS 5.3v1.02024-12-26
CVE-2024-12932 [MEDIUM] CWE-79 CVE-2024-12932: A vulnerability was found in code-projects Simple Admin Panel 1.0. It has been declared as problemat
A vulnerability was found in code-projects Simple Admin Panel 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file addSizeController.php. The manipulation of the argument size leads to cross site scripting. The attack can be launched remotely.
cvelistv5nvd
CVE-2024-12934MEDIUMCVSS 5.3v1.02024-12-26
CVE-2024-12934 [MEDIUM] CWE-74 CVE-2024-12934: A vulnerability classified as critical has been found in code-projects Simple Admin Panel 1.0. This
A vulnerability classified as critical has been found in code-projects Simple Admin Panel 1.0. This affects an unknown part of the file updateItemController.php. The manipulation of the argument p_desk leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2024-12938MEDIUMCVSS 5.3v1.02024-12-26
CVE-2024-12938 [MEDIUM] CWE-74 CVE-2024-12938: A vulnerability has been found in code-projects Simple Admin Panel 1.0 and classified as critical. A
A vulnerability has been found in code-projects Simple Admin Panel 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file updateOrderStatus.php. The manipulation of the argument record leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be us
cvelistv5nvd
CVE-2024-25223CRITICALCVSS 9.8v1.02024-02-14
CVE-2024-25223 [CRITICAL] CWE-89 CVE-2024-25223: Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID
Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminView/viewEachOrder.php.
nvd
CVE-2024-25226MEDIUMCVSS 6.1v1.02024-02-14
CVE-2024-25226 [MEDIUM] CWE-79 CVE-2024-25226: A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execut
A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter under the Add Category function.
nvd
CVE-2024-25224MEDIUMCVSS 5.4v1.02024-02-14
CVE-2024-25224 [MEDIUM] CWE-79 CVE-2024-25224: A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execut
A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Size Number parameter under the Add Size function.
nvd
CVE-2024-25225MEDIUMCVSS 5.4v1.02024-02-14
CVE-2024-25225 [MEDIUM] CWE-79 CVE-2024-25225: A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execut
A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter under the Add Category function.
nvd