Sourcecodester Simple Student Information System vulnerabilities

3 known vulnerabilities affecting sourcecodester/simple_student_information_system.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2023-2425MEDIUMCVSS 4.8v1.02023-04-29
CVE-2023-2425 [LOW] CWE-79 CVE-2023-2425: A vulnerability was found in SourceCodester Simple Student Information System 1.0. It has been class A vulnerability was found in SourceCodester Simple Student Information System 1.0. It has been classified as problematic. This affects an unknown part of the file /classes/Master.php?f=save_course of the component Add New Course. The manipulation of the argument name with the input alert(document.cookie) leads to cross site scripting. It is possible to in
cvelistv5nvd
CVE-2022-2722CRITICALCVSS 9.8vn/a2022-08-09
CVE-2022-2722 [MEDIUM] CWE-89 CVE-2022-2722: A vulnerability was found in SourceCodester Simple Student Information System and classified as crit A vulnerability was found in SourceCodester Simple Student Information System and classified as critical. This issue affects some unknown processing of the file manage_course.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated
cvelistv5nvd
CVE-2022-2705CRITICALCVSS 9.8vn/a2022-08-08
CVE-2022-2705 [MEDIUM] CWE-89 CVE-2022-2705: A vulnerability was found in SourceCodester Simple Student Information System. It has been rated as A vulnerability was found in SourceCodester Simple Student Information System. It has been rated as critical. This issue affects some unknown processing of the file admin/departments/manage_department.php. The manipulation of the argument id with the input -5756%27%20UNION%20ALL%20SELECT%20NULL,database(),user(),NULL,NULL,NULL,NULL--%20- leads to sql in
cvelistv5nvd