Phpgurukul Vehicle Parking Management System vulnerabilities

24 known vulnerabilities affecting phpgurukul/vehicle_parking_management_system.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2MEDIUM22

Vulnerabilities

Page 2 of 2
CVE-2021-37805MEDIUMCVSS 5.4v1.02021-10-27
CVE-2021-37805 [MEDIUM] CWE-79 CVE-2021-37805: A Stored Cross Site Scripting (XSS) vunerability exists in Sourcecodeste Vehicle Parking Management A Stored Cross Site Scripting (XSS) vunerability exists in Sourcecodeste Vehicle Parking Management System affected version 1.0 is via the add-vehicle.php endpoint.
nvd
CVE-2021-37806MEDIUMCVSS 5.9v1.02021-10-27
CVE-2021-37806 [MEDIUM] CWE-89 CVE-2021-37806: An SQL Injection vulnerability exists in https://phpgurukul.com Vehicle Parking Management System af An SQL Injection vulnerability exists in https://phpgurukul.com Vehicle Parking Management System affected version 1.0. The system is vulnerable to time-based SQL injection on multiple endpoints. Based on the SLEEP(N) function payload that will sleep for a number of seconds used on the (1) editid , (2) viewid, and (3) catename parameters, the server
nvd
CVE-2021-27822MEDIUMCVSS 4.8v1.02021-08-19
CVE-2021-27822 [MEDIUM] CWE-79 CVE-2021-27822: A persistent cross site scripting (XSS) vulnerability in the Add Categories module of Vehicle Parkin A persistent cross site scripting (XSS) vulnerability in the Add Categories module of Vehicle Parking Management System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Category field.
nvd
CVE-2020-23936CRITICALCVSS 9.8v1.02020-08-20
CVE-2020-23936 [CRITICAL] CWE-89 CVE-2020-23936: PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Usernam PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".
nvd