Oretnom23 Simple Online Book Store System vulnerabilities
3 known vulnerabilities affecting oretnom23/simple_online_book_store_system.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2025-63891HIGHCVSS 7.5v1.02025-11-14
CVE-2025-63891 [HIGH] CWE-200 CVE-2025-63891: Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store Syst
Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacker to disclose full database contents (including schema and credential hashes) via an unauthenticated HTTP GET request to /obs/database/obs_db.sql.
nvd
CVE-2024-6951MEDIUMCVSS 5.3v1.02024-07-21
CVE-2024-6951 [MEDIUM] CWE-89 CVE-2024-6951: A vulnerability, which was classified as critical, was found in SourceCodester Simple Online Book St
A vulnerability, which was classified as critical, was found in SourceCodester Simple Online Book Store System 1.0. This affects an unknown part of the file admin_delete.php. The manipulation of the argument bookisbn leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The
nvd
CVE-2022-37796MEDIUMCVSS 5.4v1.02022-09-12
CVE-2022-37796 [MEDIUM] CWE-79 CVE-2022-37796: In Simple Online Book Store System 1.0 in /admin_book.php the Title, Author, and Description paramet
In Simple Online Book Store System 1.0 in /admin_book.php the Title, Author, and Description parameters are vulnerable to Cross Site Scripting(XSS).
nvd