cbcvebase.

Sourcecodester Online Tours Travels Management System vulnerabilities

24 known vulnerabilities affecting sourcecodester/online_tours_travels_management_system.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH5MEDIUM7

Vulnerabilities

Page 2 of 2
CVE-2023-0531P4MEDIUMCVSS 4.7v1.02023-01-27
CVE-2023-0531 [MEDIUM] CWE-89 CVE-2023-0531: A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Manag A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Management System 1.0. Affected is an unknown function of the file admin/booking_report.php. The manipulation of the argument to_date leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be
nvd
CVE-2023-1396P4MEDIUMCVSS 6.1v1.02023-03-14
CVE-2023-1396 [MEDIUM] CWE-79 CVE-2023-1396: A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has bee A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file admin/traveller_details.php. The manipulation of the argument address leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to th
nvd
CVE-2023-0534P4MEDIUMCVSS 4.7v1.02023-01-27
CVE-2023-0534 [MEDIUM] CWE-89 CVE-2023-0534: A vulnerability, which was classified as critical, was found in SourceCodester Online Tours & Travel A vulnerability, which was classified as critical, was found in SourceCodester Online Tours & Travels Management System 1.0. This affects an unknown part of the file admin/expense_report.php. The manipulation of the argument to_date leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and
nvd
CVE-2023-0532P4MEDIUMCVSS 4.7v1.02023-01-27
CVE-2023-0532 [MEDIUM] CWE-89 CVE-2023-0532: A vulnerability classified as critical was found in SourceCodester Online Tours & Travels Management A vulnerability classified as critical was found in SourceCodester Online Tours & Travels Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/disapprove_user.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public a
nvd