Projectworlds Pvt Limited Student Result Management System vulnerabilities
4 known vulnerabilities affecting projectworlds_pvt_limited/student_result_management_system.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4
Vulnerabilities
Page 1 of 1
CVE-2023-48720CRITICALCVSS 9.8v1.02023-12-21
CVE-2023-48720 [CRITICAL] CWE-89 CVE-2023-48720: Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulner
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.
cvelistv5nvd
CVE-2023-48716CRITICALCVSS 9.8v1.02023-12-21
CVE-2023-48716 [CRITICAL] CWE-89 CVE-2023-48716: Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulner
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_id' parameter of the add_classes.php resource does not validate the characters received and they are sent unfiltered to the database.
cvelistv5nvd
CVE-2023-48722CRITICALCVSS 9.8v1.02023-12-21
CVE-2023-48722 [CRITICAL] CWE-89 CVE-2023-48722: Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulner
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_results.php resource does not validate the characters received and they are sent unfiltered to the database.
cvelistv5nvd
CVE-2023-48718CRITICALCVSS 9.8v1.02023-12-21
CVE-2023-48718 [CRITICAL] CWE-89 CVE-2023-48718: Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulner
Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_students.php resource does not validate the characters received and they are sent unfiltered to the database.
cvelistv5nvd